References https://www.twcert.org.tw/tw/cp-132-10570-72e31-1.html https://www.twcert.org.tw/newepaper/cp-151-10570-72e31-3.html https://www.cvedetails.com/cve/CVE-2025-14712/ https://www.twcert.org.tw/tw/lp-132-1-3-20.html https://www.openinfosec.com/zh/shareArticle/content/1639 https://cve.imfht.com/detail/CVE-2025-14712 https://www.sdc.org.tw/111-114/product/%E5%AD%B8%E7%94%9F%E5%AD%B8%E7%BF%92%E8%A8%BA%E6%96%B7%E8%BC%94%E5%B0%8E%E7%B3%BB%E7%B5%B1/ https://www.jhenggao.com/
Related VulnerabilitiesPoCserverless-framework-config-exposure: Serverless Framework - Configuration ExposurePoCterraformrc-credentials-exposure: Terraform CLI Configuration - Credentials ExposurePoCterraform-tfstate-exposure: Terraform State - File ExposurePoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-25703: NeuVector - Information DisclosurePoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated Initialize融易網路|GPM LIGHT - Sensitive Data ExposurePoCCVE-2026-6639: AI Copilot Content Generator <=1.4.6 - Unauthenticated Task Data ExposurePoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposurePoCqdrant-telemetry-exposure: Qdrant - Telemetry ExposurePoCCVE-2026-13153: Essential Blocks < 6.4.0 - Information DisclosurePoCflowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API Exposure