References https://www.twcert.org.tw/tw/cp-132-6738-b78f4-1.html https://www.cc.ntu.edu.tw/chinese/cert/cert20221208.asp https://www.twcert.org.tw/newepaper/cp-151-6738-b78f4-3.html https://www.kmh.klcg.gov.tw/tw/kmh1/3522-264482.html https://net.nthu.edu.tw/netsys/mailing:announcement:20221130_01?do=export_pdf https://www.twcert.org.tw/tw/lp-132-1-8-60.html https://www.twcert.org.tw/newepaper/lp-151-3-23-20.html
Related Vulnerabilities畅捷通T+ERP系统SelectBackupFileOnServer接口处存在目录遍历漏洞PoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCserverless-framework-config-exposure: Serverless Framework - Configuration ExposurePoCCVE-2025-11452: Asgaros Forum < 3.2.0 - SQL InjectionPoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated InitializePoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated Exposure全景軟體|CGServiSign - OS Command InjectionPoCCVE-2021-42392: H2 Database Console - JNDI Injection RCEPoCCVE-2026-69085: SiYuan <=3.7.2 - SQL InjectionPoCwordpress-click2shell: WordPress Click2Shell Theme Preview Selector Injection