CRITICAL🇵🇱 Wersja polska

CVE-2025-5893

CVSS 9.3v4.0pub. 2025-06-09upd. 2026-04-15

Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain plaintext administrator credentials.

🤖 AI Analysis
How it works

An attacker without any authentication can access a specific page in the web application of the system. This page discloses administrator authentication credentials stored or returned in unencrypted plaintext. The vulnerability results from improper access control to the resource and lack of encryption mechanisms or credential masking (CWE-256: plaintext storage of password, CWE-497: exposure of sensitive system data).

Impact

The attacker obtains complete administrator login credentials for the parking management system, enabling them to seize control of the system, manipulate data, and potentially gain access to the network infrastructure with which the system is integrated.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references. Additionally, until the fix is implemented, it is recommended to restrict system access exclusively to trusted IP addresses and monitor unauthorized access attempts to the administrative panel.

Who is affected

Smart Parking Management System by Honding Technology — specific versions indicated in the manufacturer's references (TWCERT).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References