References https://www.twcert.org.tw/tw/cp-132-8045-a2804-1.html https://tp2rc.tanet.edu.tw/node/914 https://www.twcert.org.tw/newepaper/cp-151-8045-a2804-3.html https://net.nthu.edu.tw/netsys/mailing:announcement:20241007_01 https://www.twcert.org.tw/en/cp-139-8046-057c2-2.html https://www.cve.org/CVERecord?id=CVE-2024-8448 https://security.glexia.com/cves/CVE-2024-8448
Related VulnerabilitiesPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCterraformrc-credentials-exposure: Terraform CLI Configuration - Credentials ExposurePoCCRMEB /api/remote_register 权限绕过漏洞PoCCVE-2025-62593: Ray < 2.52.0 - Remote Code ExecutionPoCCVE-2026-1340: Ivanti EPMM < 12.8.0.0 - Remote Code ExecutionPoCCVE-2026-86218: N-able N-central <2026.3.1.14 - Pre-Authentication Remote Code ExecutionPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoCCVE-2026-2113: tpadmin <= 1.3.12 - Remote Code Execution