go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ZONG YU Okcat Parking Management Platform - Missing Authentication

TVN ID TVN-202505007
CVE ID CVE-2025-4555
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Okcat Parking Management Platform
Description The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking records, and restarting the system.
Solution The affected product is no longer maintained. It is recommended to evaluate and adopt alternative products.
Credit Chih-Che Chang, Yu-Chieh Kuo, Li-Fan Cheng, Shi-Yi Xie, An-Wei Kung(NICS)
Public Date 2025-05-12
Top