CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.
Update CMS-WS to version 1.0.26198 or later
Update CMS-SE to version 11.0.26198 or later
Update SMP to version 4.0.26198 or later