References https://www.twcert.org.tw/tw/cp-132-10752-5a4d9-1.html https://dweb.cjcu.edu.tw/iip/news/54768 https://www.tcrc.edu.tw/new/new-list/ehg2408-stack-based-buffer-overflow https://libinfo.fgu.edu.tw/zh_tw/news/topnews/-%E6%BC%8F%E6%B4%9E%E9%A0%90%E8%AD%A6-%E4%B8%8A%E5%B0%9A%E7%A7%91%E6%8A%80%EF%BD%9CEHG2408%E7%B3%BB%E5%88%97%E4%BA%A4%E6%8F%9B%E5%99%A8-Stack-based-Buffer-Overflow-13459685 https://lic.nuk.edu.tw/p/406-1012-95992,r73.php?Lang=zh-tw https://oits.pu.edu.tw/p/406-1002-70005,r11.php?Lang=zh-tw https://www.twcert.org.tw/newepaper/cp-151-10752-5a4d9-3.html https://www.thehackerwire.com/atop-ehg2408-switch-rce-via-stack-buffer-overflow/ https://nvd.nist.gov/vuln/detail/CVE-2026-3823 https://mondoo.com/vulnerability-intelligence/vulnerability/CVE-2026-3823 https://github.com/advisories/GHSA-xwwx-hh9w-5r7f https://www.twcert.org.tw/en/cp-139-10753-e091e-2.html
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionWordPress WebStack主题 /wp-admin/admin-ajax.php 文件上传漏洞(CVE-2026-1555)CentreStack 本地文件包含漏洞(CVE-2025-11371)全程云 /OA/api/2.0/HR/EntryApply/GetBaseData SQL 注入漏洞Apache CloudStack /client/api/ 默认口令漏洞Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)ERPNext /api/method/erpnext.stock.doctype.material_request.material_request.get_material_requests_based_on_supplier SQL 注入漏洞(CVE-2025-52039)PoCCVE-2025-62613: VDO.Ninja - DOM-Based Cross-Site ScriptingPoCservicestack-requestlogs: ServiceStack Request Logs - Unauthenticated AccessPoCCVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded Credentials(CVE-2025-14611)Gladinet CentreStack和Triofox AES加密硬编码漏洞导致任意文件包含及安全降级易达科技-ECMS getProjectBaseDocData SQL注入漏洞PoC易达科技-ECMS getProjectBaseDocData 存在SQL注入漏洞