References https://www.twcert.org.tw/tw/cp-132-7966-8c6c3-1.html https://www.twcert.org.tw/newepaper/cp-151-7966-8c6c3-3.html https://devhub.checkmarx.com/cve-details/cve-2024-40720/ https://nvd.nist.gov/vuln/detail/CVE-2024-40721 https://www.cvedetails.com/cve/CVE-2024-40721/ https://github.com/advisories/GHSA-f6q3-hjwj-2j45 https://www.changingtec.com/news_detail.jsp?item_id=313 https://webnas.bhes.ntpc.edu.tw/wordpress/archives/15963 https://www.twcert.org.tw/tw/cp-132-7964-5b266-1.html
Related VulnerabilitiesPoCtp-link-wr840n-auth-bypass: TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper AuthenticationPoCCVE-2026-4987: SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via form_id技嘉科技|Gigabyte Control Center - Improper Access ControlPoCCVE-2026-32230: Uptime-Kuma < v1.23.0 - Improper Access ControlPoCCVE-2026-48710: Starlette - Improper Validation of Unsafe Equivalence in Input基點資訊|CelloOS - Improper Access ControlWindows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)PoCCVE-2021-22017: vCenter Server - Improper Access ControlPoCollama-improper-authorization: Ollama - Improper AuthorizationPoCCVE-2021-20617: Acmailer - Improper Access Control to OS Command InjectionPoCCVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File Exposure