CVE-2026-1021

Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gotac:police_statistics_database_system:*:*:*:*:*:*:*:*

History

23 Jan 2026, 20:24

Type Values Removed Values Added
References () https://www.twcert.org.tw/en/cp-139-10638-0e44b-2.html - () https://www.twcert.org.tw/en/cp-139-10638-0e44b-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10637-3e4b3-1.html - () https://www.twcert.org.tw/tw/cp-132-10637-3e4b3-1.html - Third Party Advisory
First Time Gotac police Statistics Database System
Gotac
CPE cpe:2.3:a:gotac:police_statistics_database_system:*:*:*:*:*:*:*:*

16 Jan 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 03:16

Updated : 2026-01-23 20:24


NVD link : CVE-2026-1021

Mitre link : CVE-2026-1021

CVE.ORG link : CVE-2026-1021


JSON object : View

Products Affected

gotac

  • police_statistics_database_system
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type