Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2025111903115959 | Publication Time | 2025/11/19 15:01 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/11/19 15:01 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】YuanGang Technology|ThinPLUS – OS Command Injection (CVE-2025-13284) |
|||
| [Content] Forwarded from TWCERTCC-200-202511-00000014 【YuanGang Technology|ThinPLUS – OS Command Injection】(CVE-2025-13284, CVSS: 9.8) ThinPLUS, developed by YuanGang Technology, contains an OS Command Injection vulnerability. A remote attacker without authentication can inject arbitrary operating system commands and execute them on the server. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] ThinPLUS |
|||
| [Recommended Actions] Contact the vendor to apply the update. |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-132-10512-e196b-1.html |
|||