Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026082803080909 | Publication Time | 2026-08-28 15:58:09 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-28 15:58:09 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Le Yan Co., Ltd.|Leqing Medical Management System - Remote Code Execution |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000019 【Le Yan Co., Ltd.|Leqing Medical Management System - Remote Code Execution】(CVE-2026-78685, CVSS: 8.8) The Leqing Medical Management System developed by Le Yan Co., Ltd. contains a Remote Code Execution vulnerability. An unauthenticated remote attacker may exploit a specially crafted HTML webpage to execute arbitrary operating system commands. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Leqing Medical Management System versions 2.4.2.8 to 2.5.1.9 |
|||
|
[Recommended Actions] Update to version 2.5.2.0 or later |
|||
|
[Reference] |
|||