CVE-2025-3135

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 125

Summary

CVE-2025-3135 is a newly discovered critical vulnerability affecting the fcba_zzm ICS-Park Management System version 2.1. The issue lies within the /api/system/dept/update file, which contains unknown code that is susceptible to SQL injection. An attacker can exploit this vulnerability remotely, potentially gaining unauthorized access to the system. The exploit for this vulnerability has been disclosed to the public, increasing the risk of widespread attacks. System administrators are urged to apply patches as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Powersystem Center 2020

Affected Vendors

  • SUBNET Solutions Inc.