CVE-2023-7334
Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 15, 2026
- Published Date
- January 15, 2026
- Last Updated
- May 14, 2026
- Vendor
- Changjetong Information Technology Co., Ltd.
- Product
- T+
- Description
- Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).
CVSS Scores
CVSS v4.0
9.3 - CRITICAL
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SSVC Information
- Exploitation
- poc
- Automatable
- Yes
- Technical Impact
- total
Exploit Status
- Exploited in the Wild
- Yes (2026-01-24 00:00:00 UTC) Source
References
https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62
https://www.freebuf.com/articles/web/381731.html
https://blog.csdn.net/qq_53003652/article/details/134031230
https://blog.csdn.net/u010025272/article/details/131553591
https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py
https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| The Shadowserver (via CIRCL) | 2026-01-24 00:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel