Honding Technology Smart Parking Management System Missing Authorization Vulnerability Allowing Unauthorized Administrator Account Creation

Vulnerability

A missing authorization vulnerability has been identified in the Smart Parking Management System by Honding Technology, affecting versions 1.0 through 1.4. This vulnerability allows remote attackers with regular privileges to access a specific functionality that enables the creation of administrator accounts. Once these accounts are created, attackers can log into the system using the newly created credentials.

Impact

Exploitation of this vulnerability allows for unauthorized creation of administrator accounts, which can be used to gain elevated access within the application.

Remediation

Users are advised to update the Smart Parking Management System to version 1.5 or later.

Added: Jun 9, 2025, 8:17 AM
Updated: Jun 9, 2025, 8:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.