U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
References
| Link | Resource |
|---|---|
| https://www.twcert.org.tw/en/cp-139-10743-9a952-2.html | Third Party Advisory |
| https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Mar 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Edetw
Edetw u-office Force |
|
| References | () https://www.twcert.org.tw/en/cp-139-10743-9a952-2.html - Third Party Advisory | |
| References | () https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html - Third Party Advisory | |
| CPE | cpe:2.3:a:edetw:u-office_force:29.50:-:*:*:*:*:*:* cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:* |
02 Mar 2026, 20:29
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
02 Mar 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-02 07:16
Updated : 2026-03-09 14:16
NVD link : CVE-2026-3422
Mitre link : CVE-2026-3422
CVE.ORG link : CVE-2026-3422
JSON object : View
Products Affected
edetw
- u-office_force
CWE
CWE-502
Deserialization of Untrusted Data
