Source: Ministry of education information & communication security contingency platform
| Publication Number | TACERT-ANA-2025051309053434 | Publication Time | 2025/05/13 09:08 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/05/13 09:08 |
| Impact Level | Low | ||
| [Subject] [Vulnerability Alert] Two Critical Information Security Vulnerabilities Found in ZONG YU TEK ZYT-Management Platform |
|||
| [Content] Forwarded from TWCERTCC-200-202505-00000009 [ZONG YU TEK ZYT-Management Platform - okcat - Missing Authentication] (CVE-2025-4555, CVSS: 9.8) The web-based management interface of ZONG YU TEK's ZYT-Management Platform - okcat contains a Missing Authentication vulnerability. Remote unauthenticated attackers may directly access system functions such as opening gates, viewing license plates and parking records, and performing system reboots. [ZONG YU TEK ZYT-Management Platform - okcat - Arbitrary File Upload] (CVE-2025-4556, CVSS: 9.8) The web-based management interface of ZONG YU TEK's ZYT-Management Platform - okcat contains an Arbitrary File Upload vulnerability. Remote unauthenticated attackers can upload and execute web shell backdoors, enabling arbitrary code execution on the server side. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] ZYT-Management Platform – okcat |
|||
| [Recommended Actions] The affected product is no longer maintained. It is recommended to assess and consider using alternative products. |
|||
| [Reference] ZONG YU TEK ZYT-Management Platform – okcat - Missing Authentication: https://www.twcert.org.tw/tw/cp-132-10108-f77f5-1.html ZONG YU TEK ZYT-Management Platform – okcat - Arbitrary File Upload: https://www.twcert.org.tw/tw/cp-132-10110-114f0-1.html |
|||