PatchSiren

Zhonglun CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Zhonglun CVE published 2026-09-25

CVE-2026-97871

A vulnerability was found in Zhonglun CloudPos up to 3.0.1.76, affecting the OpenLocalBrowser function in JSBridge. This issue allows for code injection via manipulation of the url argument. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted but did not respond. Defenders should assess exposure and prioritize verification of affected syst [truncated]

LOW Zhonglun CVE published 2026-09-25

CVE-2026-97866

A weakness in Zhonglun CloudPOS 3.0's Automatic Update functionality can lead to channel accessible by non-endpoint. This issue, tracked as CVE-2026-97866, has a CVSS score of 2.9 and is considered low severity. The vulnerability is difficult to exploit and requires complex attacks. A public exploit is available, but the vendor did not respond to early disclosure.