互動資通 EVERY8D 內部 SMS 路由管理平台開發伺服器公開對外,JS Bundle 洩漏電信帳號管理架構及完整 API 端點 - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2026-00640
  •  發信 Vendor: 互動資通股份有限公司
  • Title: 互動資通 EVERY8D 內部 SMS 路由管理平台開發伺服器公開對外,JS Bundle 洩漏電信帳號管理架構及完整 API 端點
  • Introduction: SMS 路由管理平台開發實例公開對外,未認證即可下載所有 JS Bundle,揭露電信帳號欄位及 15+ 個管理 API 端點。

處理狀態

目前狀態

公開
Last Update : 2026/08/05
  • 新提交
  • 已審核
  • 已通報
  • 已修補
  • 已複測
  • 公開

處理歷程

  • 2026/05/07 02:17:17 : 新提交 (由 罐頭 更新此狀態)
  • 2026/05/14 13:03:31 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/05/27 15:56:49 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/05/27 15:56:49 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/06/29 10:22:01 : 已修補 (由 組織帳號 更新此狀態)
  • 2026/06/29 11:35:38 : 複測申請中 (由 組織帳號 更新此狀態)
  • 2026/06/29 11:38:38 : 已修補 (由 組織帳號 更新此狀態)
  • 2026/07/06 11:23:28 : 延期申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/07/08 15:13:28 : 延期申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/07/30 20:35:45 : 複測申請中 (由 組織帳號 更新此狀態)
  • 2026/08/01 14:47:53 : 確認已修補 (由 罐頭 更新此狀態)
  • 2026/08/05 03:00:11 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

  • ZDID:ZD-2026-00640
  • 通報者:guan4tou2 (罐頭)
  • 風險:中
  • 類型:資訊洩漏 (Information Leakage)

參考資料

攻擊者可利用洩漏資訊進行下一步攻擊行為。

OWASP 漏洞說明 (Top 10 2017 - A3 Sensitive Data Exposure)
https://www.owasp.org/index.php/Top_10-2017_A3-Sensitive_Data_Exposure

CWE-200 漏洞說明
https://cwe.mitre.org/data/definitions/200.html
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

https://rd1-dev.teamplus.com.tw
https://rd1-dev.teamplus.com.tw/assets/OpsOutboundSourceAddressesView-PNjGtL8D.js
https://rd1-dev.teamplus.com.tw/assets/OpsDbConnectionsView-BvtX5aK7.js
https://rd1-dev.teamplus.com.tw/assets/axios-BSiZYRco.js

敘述

漏洞概述

互動資通用於管理 EVERY8D SMS 路由基礎設施的內部管理平台(開發環境)直接暴露在 Internet 上。雖然 API 端點需要認證才能存取實際資料,但前端 JS Bundle 揭示了平台所管理的高敏感度資料類型,攻擊者可以此為目標進行更深入的攻擊(如暴力破解弱密碼、尋找其他認證繞過方式)。

重現步驟(Live verified: 2026-05-07)

步驟 1:確認平台公開可達

curl -sI "https://rd1-dev.teamplus.com.tw"
# → HTTP/2 200
# → server: Caddy
# → Content-Type: text/html; charset=utf-8

步驟 2:讀取首頁 HTML,獲取 JS Bundle 清單

curl -s "https://rd1-dev.teamplus.com.tw"

回應(完整 HTML):

<!doctype html>
<html lang="zh-TW">
  <head>
    <meta charset="UTF-8" />
    <title>EVERY8D 管理平台</title>
    <script type="module" crossorigin src="/assets/index-DAz7Ip8l.js"></script>
    <link rel="modulepreload" crossorigin href="/assets/auth-DD52QjHl.js">
    ...
  </head>
  <body><div id="app"></div></body>
</html>

主 Bundle 的 __vite__mapDeps 揭示所有懶載入 chunk:

  • OpsDbConnectionsView-BvtX5aK7.js — MongoDB 連線字串管理
  • OpsOutboundSourceAddressesView-PNjGtL8D.js — 電信帳號管理
  • AdminUsersView-2LdBLcMx.js — 管理員帳號管理
  • SSOLoginView-NZeYdaz-.js — TeamPlus SSO 登入

步驟 3:讀取電信帳號管理 Bundle,揭示 CHT/TWM/TATA 帳號結構

curl -s "https://rd1-dev.teamplus.com.tw/assets/OpsOutboundSourceAddressesView-PNjGtL8D.js" > ops.js
grep -o 'cht_account\|twm_account\|tata_account\|sms_account\|sms_mima\|mms_account\|mms_mima' ops.js | sort | uniq

結果揭示以下資料欄位:

cht_account.sms_account     ← 中華電信 SMS 帳號
cht_account.sms_mima        ← 中華電信 SMS 密碼
cht_account.mms_account     ← 中華電信 MMS 帳號
cht_account.mms_mima        ← 中華電信 MMS 密碼
twm_account.sms_account     ← 台灣大哥大 SMS 帳號
twm_account.sms_mima        ← 台灣大哥大 SMS 密碼
twm_account.mms_account     ← 台灣大哥大 MMS 帳號
twm_account.mms_mima        ← 台灣大哥大 MMS 密碼
tata_account.account        ← TATA Communications 帳號
tata_account.mima           ← TATA Communications 密碼

並揭示 outbox_db_info 欄位(SMS Outbox DB 連線 ID 及資料庫名稱)。

步驟 4:讀取 axios Bundle 末尾,獲取完整 API 端點清單

curl -s "https://rd1-dev.teamplus.com.tw/assets/axios-BSiZYRco.js" | tail -c 3000

結果(節錄):

// Ops API
{
  getDbConnections: e => Q.get(`/manager/api/ops/db-connections`, {params: e}),
  createDbConnection: e => Q.post(`/manager/api/ops/db-connections`, e),
  getDbConnection: e => Q.get(`/manager/api/ops/db-connections/${e}`),
  updateDbConnection: (e, t) => Q.patch(`/manager/api/ops/db-connections/${e}`, t),
  getOutboundSourceAddresses: e => Q.get(`/manager/api/ops/outbound-source-addresses`, {params: e}),
  createOutboundSourceAddress: e => Q.post(`/manager/api/ops/outbound-source-addresses`, e),
  getOutboundSourceAddress: e => Q.get(`/manager/api/ops/outbound-source-addresses/${btoa(e)...}`),
  updateOutboundSourceAddress: (e, t) => Q.patch(...),
  deleteOutboundSourceAddress: e => Q.delete(...),
  getOutboundSourceAddressShortcodes: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-shortcodes`),
  getOutboundSourceAddressesForSmsRoute: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-for-sms-route`),
  getOutboundSourceAddressesForIntlRoute: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-for-intl-route`),
  getOutboundSourceAddressesForMmsRoute: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-for-mms-route`)
}
// Admin Users API  
{
  getUsers: e => Q.get(`/manager/api/admin/users`, {params: e}),
  createUser: e => Q.post(`/manager/api/admin/users`, e),
  deleteUser: e => Q.delete(`/manager/api/admin/users/${e}`),
  resetUserMfa: e => Q.post(`/manager/api/admin/users/${e}/reset-mfa`),
  resetUserMima: (e, t) => Q.post(`/manager/api/admin/users/${e}/reset-mima`, {reset_mima: t}),
  getUserFromTeamplus: e => Q.get(`/manager/api/admin/get-user-from-teamplus/${e}`)
}
// Auth
// POST /manager/api/auth/login (HTTP Basic Auth)
// POST /manager/api/auth/teamplus-sso
// POST /manager/api/auth/refresh-token
// POST /manager/api/auth/mfa

步驟 5:確認 API 端點存在(均需認證)

curl -s "https://rd1-dev.teamplus.com.tw/manager/api/ops/db-connections"
# → {"error":"unauthorized","description":"No authentication token was provided or it is invalid."}

curl -s "https://rd1-dev.teamplus.com.tw/manager/api/ops/outbound-source-addresses"
# → {"error":"unauthorized","description":"No authentication token was provided or it is invalid."}

curl -s "https://rd1-dev.teamplus.com.tw/manager/api/admin/users"
# → {"error":"unauthorized","description":"No authentication token was provided or it is invalid."}

已驗證影響(Verified)

  • ✅ rd1-dev.teamplus.com.tw 對 Internet 公開,回傳 HTTP 200(2026-05-07 重新確認 live)
  • ✅ 所有 JS Bundle 可不經認證下載
  • ✅ OpsOutboundSourceAddressesView bundle 揭示 CHT/TWM/TATA 電信帳號欄位結構(sms_account, sms_mima, mms_account, mms_mima)
  • ✅ OpsDbConnectionsView bundle 揭示 MongoDB 連線字串管理介面
  • ✅ axios bundle 揭示完整 API 端點清單(15+ 個端點)
  • ✅ API 端點存在且正確返回 401(未授權),確認後端 API 架構為真實

潛在影響(Potential)

  • 攻擊者利用此洩漏的 API 架構,針對 /manager/api/auth/login(HTTP Basic Auth)進行暴力破解
  • 若取得有效認證,可讀取所有電信帳號(CHT/TWM/TATA)及 MongoDB 連線字串
  • 可修改電信帳號設定,影響 EVERY8D 所有客戶的 SMS/MMS 發送服務

應用程式架構洩漏摘要

Bundle 大小 揭示內容
index-DAz7Ip8l.js 160,734 B 路由結構、SSO 整合、角色定義(sys_admin/ops_engineer)
OpsOutboundSourceAddressesView-PNjGtL8D.js 16,350 B CHT/TWM/TATA SMS/MMS 帳號+密碼欄位定義
OpsDbConnectionsView-BvtX5aK7.js 8,232 B MongoDB 連線字串管理 UI
AdminUsersView-2LdBLcMx.js 10,257 B 管理員 CRUD、MFA 重設、密碼重設
axios-BSiZYRco.js 41,510 B 完整 API 端點(20+ 個),HTTP Basic Auth 登入機制

修補建議

1. 立即:為 rd1-dev.teamplus.com.tw 加上 IP 白名單或 VPN 限制,停止公開存取
2. 立即:同時稽核其他 rd*.teamplus.com.tw 子域名,確認均受適當保護
3. 短期:生產與開發環境應完全隔離,開發環境不得使用生產電信帳號或真實 MongoDB 連線字串

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;