go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ZONG YU Okcat Parking Management Platform - Arbitrary File Upload

TVN ID TVN-202505008
CVE ID CVE-2025-4556
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Okcat Parking Management Platform
Description The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Solution The affected product is no longer maintained. It is recommended to evaluate and adopt alternative products.
Credit Chih-Che Chang, Yu-Chieh Kuo, Li-Fan Cheng, Shi-Yi Xie, An-Wei Kung(NICS)
Public Date 2025-05-12
Top