Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-00640
- Vendor: 互動資通股份有限公司
- Title: 互動資通 EVERY8D 內部 SMS 路由管理平台開發伺服器公開對外,JS Bundle 洩漏電信帳號管理架構及完整 API 端點
- Introduction: SMS 路由管理平台開發實例公開對外,未認證即可下載所有 JS Bundle,揭露電信帳號欄位及 15+ 個管理 API 端點。
處理狀態
目前狀態
公開
Last Update : 2026/08/05
-
新提交
-
已審核
-
已通報
-
已修補
-
已複測
-
公開
處理歷程
- 2026/05/07 02:17:17 : 新提交 (由 罐頭 更新此狀態)
- 2026/05/14 13:03:31 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/27 15:56:49 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/27 15:56:49 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/06/29 10:22:01 : 已修補 (由 組織帳號 更新此狀態)
- 2026/06/29 11:35:38 : 複測申請中 (由 組織帳號 更新此狀態)
- 2026/06/29 11:38:38 : 已修補 (由 組織帳號 更新此狀態)
- 2026/07/06 11:23:28 : 延期申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/08 15:13:28 : 延期申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/30 20:35:45 : 複測申請中 (由 組織帳號 更新此狀態)
- 2026/08/01 14:47:53 : 確認已修補 (由 罐頭 更新此狀態)
- 2026/08/05 03:00:11 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-00640
- 通報者:guan4tou2 (罐頭)
- 風險:中
- 類型:資訊洩漏 (Information Leakage)
參考資料
攻擊者可利用洩漏資訊進行下一步攻擊行為。
OWASP 漏洞說明 (Top 10 2017 - A3 Sensitive Data Exposure)
https://www.owasp.org/index.php/Top_10-2017_A3-Sensitive_Data_Exposure
CWE-200 漏洞說明
https://cwe.mitre.org/data/definitions/200.html
OWASP 漏洞說明 (Top 10 2017 - A3 Sensitive Data Exposure)
https://www.owasp.org/index.php/Top_10-2017_A3-Sensitive_Data_Exposure
CWE-200 漏洞說明
https://cwe.mitre.org/data/definitions/200.html
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)
相關網址
https://rd1-dev.teamplus.com.tw
https://rd1-dev.teamplus.com.tw/assets/OpsOutboundSourceAddressesView-PNjGtL8D.js
https://rd1-dev.teamplus.com.tw/assets/OpsDbConnectionsView-BvtX5aK7.js
https://rd1-dev.teamplus.com.tw/assets/axios-BSiZYRco.js
https://rd1-dev.teamplus.com.tw/assets/OpsOutboundSourceAddressesView-PNjGtL8D.js
https://rd1-dev.teamplus.com.tw/assets/OpsDbConnectionsView-BvtX5aK7.js
https://rd1-dev.teamplus.com.tw/assets/axios-BSiZYRco.js
敘述
漏洞概述
互動資通用於管理 EVERY8D SMS 路由基礎設施的內部管理平台(開發環境)直接暴露在 Internet 上。雖然 API 端點需要認證才能存取實際資料,但前端 JS Bundle 揭示了平台所管理的高敏感度資料類型,攻擊者可以此為目標進行更深入的攻擊(如暴力破解弱密碼、尋找其他認證繞過方式)。
重現步驟(Live verified: 2026-05-07)
步驟 1:確認平台公開可達
curl -sI "https://rd1-dev.teamplus.com.tw"
# → HTTP/2 200
# → server: Caddy
# → Content-Type: text/html; charset=utf-8
步驟 2:讀取首頁 HTML,獲取 JS Bundle 清單
curl -s "https://rd1-dev.teamplus.com.tw"
回應(完整 HTML):
<!doctype html>
<html lang="zh-TW">
<head>
<meta charset="UTF-8" />
<title>EVERY8D 管理平台</title>
<script type="module" crossorigin src="/assets/index-DAz7Ip8l.js"></script>
<link rel="modulepreload" crossorigin href="/assets/auth-DD52QjHl.js">
...
</head>
<body><div id="app"></div></body>
</html>
主 Bundle 的 __vite__mapDeps 揭示所有懶載入 chunk:
OpsDbConnectionsView-BvtX5aK7.js— MongoDB 連線字串管理OpsOutboundSourceAddressesView-PNjGtL8D.js— 電信帳號管理AdminUsersView-2LdBLcMx.js— 管理員帳號管理SSOLoginView-NZeYdaz-.js— TeamPlus SSO 登入
步驟 3:讀取電信帳號管理 Bundle,揭示 CHT/TWM/TATA 帳號結構
curl -s "https://rd1-dev.teamplus.com.tw/assets/OpsOutboundSourceAddressesView-PNjGtL8D.js" > ops.js
grep -o 'cht_account\|twm_account\|tata_account\|sms_account\|sms_mima\|mms_account\|mms_mima' ops.js | sort | uniq
結果揭示以下資料欄位:
cht_account.sms_account ← 中華電信 SMS 帳號
cht_account.sms_mima ← 中華電信 SMS 密碼
cht_account.mms_account ← 中華電信 MMS 帳號
cht_account.mms_mima ← 中華電信 MMS 密碼
twm_account.sms_account ← 台灣大哥大 SMS 帳號
twm_account.sms_mima ← 台灣大哥大 SMS 密碼
twm_account.mms_account ← 台灣大哥大 MMS 帳號
twm_account.mms_mima ← 台灣大哥大 MMS 密碼
tata_account.account ← TATA Communications 帳號
tata_account.mima ← TATA Communications 密碼
並揭示 outbox_db_info 欄位(SMS Outbox DB 連線 ID 及資料庫名稱)。
步驟 4:讀取 axios Bundle 末尾,獲取完整 API 端點清單
curl -s "https://rd1-dev.teamplus.com.tw/assets/axios-BSiZYRco.js" | tail -c 3000
結果(節錄):
// Ops API
{
getDbConnections: e => Q.get(`/manager/api/ops/db-connections`, {params: e}),
createDbConnection: e => Q.post(`/manager/api/ops/db-connections`, e),
getDbConnection: e => Q.get(`/manager/api/ops/db-connections/${e}`),
updateDbConnection: (e, t) => Q.patch(`/manager/api/ops/db-connections/${e}`, t),
getOutboundSourceAddresses: e => Q.get(`/manager/api/ops/outbound-source-addresses`, {params: e}),
createOutboundSourceAddress: e => Q.post(`/manager/api/ops/outbound-source-addresses`, e),
getOutboundSourceAddress: e => Q.get(`/manager/api/ops/outbound-source-addresses/${btoa(e)...}`),
updateOutboundSourceAddress: (e, t) => Q.patch(...),
deleteOutboundSourceAddress: e => Q.delete(...),
getOutboundSourceAddressShortcodes: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-shortcodes`),
getOutboundSourceAddressesForSmsRoute: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-for-sms-route`),
getOutboundSourceAddressesForIntlRoute: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-for-intl-route`),
getOutboundSourceAddressesForMmsRoute: e => Q.get(`/manager/api/ops/outbound-source-addresses/get-for-mms-route`)
}
// Admin Users API
{
getUsers: e => Q.get(`/manager/api/admin/users`, {params: e}),
createUser: e => Q.post(`/manager/api/admin/users`, e),
deleteUser: e => Q.delete(`/manager/api/admin/users/${e}`),
resetUserMfa: e => Q.post(`/manager/api/admin/users/${e}/reset-mfa`),
resetUserMima: (e, t) => Q.post(`/manager/api/admin/users/${e}/reset-mima`, {reset_mima: t}),
getUserFromTeamplus: e => Q.get(`/manager/api/admin/get-user-from-teamplus/${e}`)
}
// Auth
// POST /manager/api/auth/login (HTTP Basic Auth)
// POST /manager/api/auth/teamplus-sso
// POST /manager/api/auth/refresh-token
// POST /manager/api/auth/mfa
步驟 5:確認 API 端點存在(均需認證)
curl -s "https://rd1-dev.teamplus.com.tw/manager/api/ops/db-connections"
# → {"error":"unauthorized","description":"No authentication token was provided or it is invalid."}
curl -s "https://rd1-dev.teamplus.com.tw/manager/api/ops/outbound-source-addresses"
# → {"error":"unauthorized","description":"No authentication token was provided or it is invalid."}
curl -s "https://rd1-dev.teamplus.com.tw/manager/api/admin/users"
# → {"error":"unauthorized","description":"No authentication token was provided or it is invalid."}
已驗證影響(Verified)
- ✅
rd1-dev.teamplus.com.tw對 Internet 公開,回傳 HTTP 200(2026-05-07 重新確認 live) - ✅ 所有 JS Bundle 可不經認證下載
- ✅
OpsOutboundSourceAddressesViewbundle 揭示 CHT/TWM/TATA 電信帳號欄位結構(sms_account, sms_mima, mms_account, mms_mima) - ✅
OpsDbConnectionsViewbundle 揭示 MongoDB 連線字串管理介面 - ✅
axiosbundle 揭示完整 API 端點清單(15+ 個端點) - ✅ API 端點存在且正確返回 401(未授權),確認後端 API 架構為真實
潛在影響(Potential)
- 攻擊者利用此洩漏的 API 架構,針對
/manager/api/auth/login(HTTP Basic Auth)進行暴力破解 - 若取得有效認證,可讀取所有電信帳號(CHT/TWM/TATA)及 MongoDB 連線字串
- 可修改電信帳號設定,影響 EVERY8D 所有客戶的 SMS/MMS 發送服務
應用程式架構洩漏摘要
| Bundle | 大小 | 揭示內容 |
|---|---|---|
index-DAz7Ip8l.js |
160,734 B | 路由結構、SSO 整合、角色定義(sys_admin/ops_engineer) |
OpsOutboundSourceAddressesView-PNjGtL8D.js |
16,350 B | CHT/TWM/TATA SMS/MMS 帳號+密碼欄位定義 |
OpsDbConnectionsView-BvtX5aK7.js |
8,232 B | MongoDB 連線字串管理 UI |
AdminUsersView-2LdBLcMx.js |
10,257 B | 管理員 CRUD、MFA 重設、密碼重設 |
axios-BSiZYRco.js |
41,510 B | 完整 API 端點(20+ 個),HTTP Basic Auth 登入機制 |
修補建議
1. 立即:為 rd1-dev.teamplus.com.tw 加上 IP 白名單或 VPN 限制,停止公開存取
2. 立即:同時稽核其他 rd*.teamplus.com.tw 子域名,確認均受適當保護
3. 短期:生產與開發環境應完全隔離,開發環境不得使用生產電信帳號或真實 MongoDB 連線字串
擷圖
留言討論
登入後留言
聯絡組織
發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。