#qinglong

2 posts · Last used 27d

Back to Timeline
NeuroWinter @NeuroWinter@infosec.exchange · Jul 19, 2026
Replying to @NeuroWinter@infosec.exchange
3/ Qinglong turns out to be a webui for cron jobs. “wool farmers” (薅羊毛, pulling wool) use it to run scripts on a schedule that drain loyalty points, coupons and lottery payouts from apps, then cash out on xianyu / pinduoduo. qlk was a pile of exactly these. #Qinglong
0
1
0
OffSequence @offseq@infosec.exchange · Jul 16, 2026
CVE-2026-55445: Qinglong <2.20.1 has a CRITICAL improper authentication bug (CVSS 9.3). Attackers can reset admin credentials on initialized systems via /open/user/init. Upgrade to 2.20.1 ASAP. https://radar.offseq.com/threat/cve-2026-55445-cwe-287-improper-authentication-in--3a378a9a77ee78d0 #OffSeq #CVE202655445 #Vuln #Qinglong
0
0
0

You've seen all posts