IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by manipulating the web front-end.
Access control logic is enforced only on the client side (web interface) and not on the server side. An attacker can manipulate requests sent to the web application — for example, by modifying parameters, headers, or form data — to bypass permission verification. As a result, the server accepts administrative operations without verifying whether the requesting user has appropriate permissions.
Attacker gains full administrator privileges in the system, enabling them to read, modify, or delete data and take control of the application. The vulnerability is exploitable remotely without authentication, making it particularly dangerous in network-accessible environments.
Apply patches available from the manufacturer in accordance with references published by TWCERT: https://www.twcert.org.tw/en/cp-139-10653-117a1-2.html and https://www.twcert.org.tw/tw/cp-132-10652-4cdca-1.html. Until the fix is deployed, it is recommended to restrict access to the web interface to trusted networks or IP addresses only through a firewall.
IAQS and I6 products from JNC — versions specified in manufacturer references (TWCERT).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X