References https://zhuanlan.zhihu.com/p/1932214870562047555 https://zhuanlan.zhihu.com/p/4249525215 https://kb.hillstonenet.com/cn/tag/%E7%BB%BC%E5%90%88%E6%97%A5%E5%BF%97%E5%AE%A1%E8%AE%A1%E5%B9%B3%E5%8F%B0/ https://kb.hillstonenet.com/cn/ug-hsa-20r3-cn/ https://kb.hillstonenet.com/cn/tag/%E6%97%A5%E5%BF%97%E5%AE%A1%E8%AE%A1%E5%B9%B3%E5%8F%B0/ https://www.amx2418.com/product_service/operation-and-analysis/hsa/ https://kb.hillstonenet.com/cn/hsa-product-introduction/ https://kb.hillstonenet.com/cn/hsa-upload-error-insufficient-memory/
Related VulnerabilitiesPoCCVE-2026-10818: WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File UploadQAnything /api/local_doc_qa/upload_files 文件上传漏洞(CVE-2026-88533)PoCCVE-2024-57728: SimpleHelp <= 5.5.7 - Arbitrary File UploadPoCCVE-2026-84434: WordPress Gravity Forms Plugin <=3.1.0.4 - Unauthenticated Arbitrary File UploadPoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerFileRise /uploads 文件读取漏洞(CVE-2026-25231)鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File Upload網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-0558: LolLMS <= 2.2.0 - Unauthenticated File UploadPoCCVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Arbitrary File UploadPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File Upload