Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026012808015151 | Publication Time | 2026/01/28 08:52 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/01/28 08:52 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】WeiQiao Information | Single Sign-On and Electronic Directory Service System – Two Vulnerabilities Identified |
|||
|
[Content] 【WeiQiao Information | Single Sign-On and Electronic Directory Service System – OS Command Injection】 (CVE-2026-1428, CVSS: 8.8) An OS Command Injection vulnerability exists in the Single Sign-On and Electronic Directory Service System. An authenticated remote attacker can inject arbitrary operating system commands and execute them on the server." |
|||
| [Affected Platform] Electronic Directory Service System (V4) versions earlier than IFTOP_P4_181 (exclusive) |
|||
| [Recommended Actions] Update the Electronic Directory Service System (V4) to IFTOP_P4_181 or later. |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-132-10654-23f40-1.html |
|||