bug_poc in the mainfunction.cgi use ida could find the bug. when http aciton=toLogin2FA can hacked assign CVE-2020-19664