Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain plaintext administrator credentials.
An attacker without any authentication can access a specific page in the web application of the system. This page discloses administrator authentication credentials stored or returned in unencrypted plaintext. The vulnerability results from improper access control to the resource and lack of encryption mechanisms or credential masking (CWE-256: plaintext storage of password, CWE-497: exposure of sensitive system data).
The attacker obtains complete administrator login credentials for the parking management system, enabling them to seize control of the system, manipulate data, and potentially gain access to the network infrastructure with which the system is integrated.
Apply patches available from the manufacturer in accordance with the references. Additionally, until the fix is implemented, it is recommended to restrict system access exclusively to trusted IP addresses and monitor unauthorized access attempts to the administrative panel.
Smart Parking Management System by Honding Technology — specific versions indicated in the manufacturer's references (TWCERT).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X