References https://www.ddpoc.com/DVB-2025-9001.html https://cn-sec.com/archives/3922830.html https://www.bigant.cn/article/news.html https://zhuanlan.zhihu.com/p/1932214870562047555 https://cn-sec.com/archives/tag/%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E/page/2 https://www.ddpoc.com/DVB-2022-3871.html https://cn-sec.com/archives/3922830.html https://www.cnvd.org.cn/flaw/show/CNVD-2020-58418 https://vulncheck.com/blog/bigant-cve-2025-0364 https://vulncheck.com/advisories/big-ant-upload-rce
Related Vulnerabilities中科商软云连ERP /admin/session!ajaxList.action 未授权访问漏洞PoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCCVE-2026-2113: tpadmin <= 1.3.12 - Remote Code ExecutionPoCnacos-v3-auth-scope-bypass: Nacos 3.x - Unauthenticated Admin Takeovertpadmin存在远程代码执行漏洞(CVE-2026-2113)PoCCVE-2026-19598: Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX RouterPoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCCVE-2025-13342: DynamiApps Frontend Admin <= 3.28.20 - Unauthenticated Arbitrary Options UpdatePoCCVE-2026-34976: Dgraph <=v25.3.0 - Admin Mutation Missing AuthorizationPoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosureCisco ISE /admin/files-upload/ 文件上传漏洞(CVE-2025-20282)PoCCVE-2026-8732: WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauthenticated Administrator Account CreationPoCNginxWebUI /adminPage/login/getAuth 命令执行漏洞