CVE-2025-3135
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 125
Summary
CVE-2025-3135 is a newly discovered critical vulnerability affecting the fcba_zzm ICS-Park Management System version 2.1. The issue lies within the /api/system/dept/update file, which contains unknown code that is susceptible to SQL injection. An attacker can exploit this vulnerability remotely, potentially gaining unauthorized access to the system. The exploit for this vulnerability has been disclosed to the public, increasing the risk of widespread attacks. System administrators are urged to apply patches as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Powersystem Center 2020
Affected Vendors
- SUBNET Solutions Inc.