References https://www.twcert.org.tw/tw/cp-132-6681-e9650-1.html https://vuldb.com/vuln/213433 https://nvd.nist.gov/vuln/detail/CVE-2022-38122 https://www.twcert.org.tw/newepaper/cp-151-6681-e9650-3.html https://cwe.mitre.org/data/definitions/319.html https://www.cvedetails.com/product/123403/Upspowercom-Upsmon-Pro.html?vendor_id=28669
Related VulnerabilitiesPoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-25703: NeuVector - Information DisclosurePoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data Access融易網路|GPM LIGHT - Sensitive Data ExposurePoCCVE-2026-13153: Essential Blocks < 6.4.0 - Information DisclosurePoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information DisclosurePoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-27796: Homarr < 1.54.0 - Information DisclosurePoCCVE-2026-1980: WPBookit <= 1.0.8 - Unauthenticated Customer Information DisclosurePoCCVE-2026-8386: WP Go Maps < 10.0.10 - Unauthenticated Marker Information DisclosurePoCCVE-2026-22778: vLLM 0.8.3 - 0.14.0 - Information DisclosurePoCCVE-2026-8383: LearnPress < 4.3.7 - Information DisclosurePoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information Disclosure