References https://www.twcert.org.tw/tw/cp-132-7347-2653e-1.html https://www.twcert.org.tw/newepaper/cp-151-7347-2653e-3.html https://www.twcert.org.tw/tw/lp-132-1-7-60.html https://www.twcert.org.tw/newepaper/lp-151-3-19-20.html
Related VulnerabilitiesPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞仁和兴业(深圳)软件有限公司仁和云ERPbackupexportall 接口存在任意文件读取漏洞PoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosuremetaBase reset_password 接口存在sql注入漏洞Versa Concerto /portalapi/v1/roles/option 权限绕过漏洞(CVE-2025-34027)PoCCVE-2026-44551: Open WebUI 'LDAP Empty Password' - Authentication BypassTRUfusion Enterprise /trufusionPortal/getProjectList 权限绕过漏洞(CVE-2025-27223)WIFISKY 7层流控路由器 /portal/ibilling/index.php 命令执行漏洞大华智慧园区综合管理平台 /portal/itc/attachment_downloadByUrlAtt.action 文件读取漏洞HIKVISION 综合安防管理平台 /artemis-portal/artemis/env 信息泄露漏洞PoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password Recovery用友NC /portal/pt/M0dUlE/redeploy SQL 注入漏洞