All 7 CVE vulnerabilities found in DDI Central, with AI-generated Chinese analysis, references, and POCs.
Vendor: ManageEngine
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-12265 | Missing Authorization on HA Failover Config allows Complete Data Destruction | 8.8 | High | 2026-09-28 |
| CVE-2026-12264 | Authenticated File Write via HA Failover Config Upload leads to RCE | 8.8 | High | 2026-09-28 |
| CVE-2026-12267 | Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE CWE-20 | 7.2 | High | 2026-09-28 |
| CVE-2026-12268 | Authenticated PowerShell Injection leads to RCE CWE-20 | 8.8 | High | 2026-09-28 |
| CVE-2026-12269 | Authenticated File Write to RCE via keepalived in DDI Central CWE-434 | 8.8 | High | 2026-09-28 |
| CVE-2024-5471 | Agent takeover CWE-798 | 8.8 | High | 2024-07-17 |
| CVE-2024-27311 | Arbitrary file writing CWE-434 | 5.5 | Medium | 2024-07-17 |
All 7 known CVE vulnerabilities affecting DDI Central with full Chinese analysis, references, and POCs where available.