CVE-2025-4557 Details
Description
The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.
A missing authentication vulnerability has been identified in the Parking Management System by ZONG YU. This issue allows unauthenticated remote attackers to access specific APIs and perform system functions, such as opening gates and restarting the system.
The affected product is no longer maintained. It is recommended to evaluate and adopt alternative products.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2025CISA-ADP
Assessed May 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-10113-58c29-2.html | [email protected] | AdvisoryRemedy |
| https://www.twcert.org.tw/tw/cp-132-10112-5de7e-1.html | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ZONG YU Parking Management System | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2025 | CVE Modified | [email protected] |
| May 12, 2025 | New CVE Received | [email protected] |
Volerion