Missing Authentication Vulnerability in ZONG YU Parking Management System
CVE-2025-4557

8.8HIGH

Key Information:

Vendor

Zong Yu

Vendor
CVE Published:
12 May 2025

What is CVE-2025-4557?

The Parking Management System developed by ZONG YU suffers from a Missing Authentication vulnerability in its specific APIs. This flaw enables unauthenticated remote attackers to gain access to critical system functions, including the ability to open gates and restart the system. Without proper authentication mechanisms in place, attackers can exploit this vulnerability to manipulate system operations, potentially leading to unauthorized access and control over the parking management infrastructure.

Affected Version(s)

Parking Management System 0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-4557 : Missing Authentication Vulnerability in ZONG YU Parking Management System