Forwarded from Taiwan Computer Network Emergency Response Team/Coordination Center TWCERTCC-200-202509-00000007
[CVE-2025-55141, CVSS: 8.8] This vulnerability, a lack of authorization mechanism, allows an authenticated attacker with read-only administrator privileges to modify authentication-related settings.
[CVE-2025-55142, CVSS: 8.8] This vulnerability, a lack of authorization mechanism, allows an authenticated attacker with read-only administrator privileges to modify authentication-related settings.
[CVE-2025-55145, CVSS: 8.9] This vulnerability, a lack of authorization mechanism, allows an authenticated remote attacker to hijack existing HTML5 connections.
[CVE-2025-55147, CVSS: 8.8] This vulnerability is a CSRF vulnerability that allows an authenticated remote attacker to perform sensitive operations as the victim user.