go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ZONG YU Parking Management System - Missing Authentication

TVN ID TVN-202505009
CVE ID CVE-2025-4557
CVSS 9.1 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected Products Parking Management System
Description The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.
Solution The affected product is no longer maintained. It is recommended to evaluate and adopt alternative products.
Credit Chih-Che Chang, Yu-Chieh Kuo, Li-Fan Cheng, Shi-Yi Xie, An-Wei Kung(NICS)
Public Date 2025-05-12
Top