Impact
ICS‑Park Smart Park Management System v2.0 contains an unrestricted file upload flaw in its file upload module that permits a remote attacker to upload arbitrary files and execute code on the server. This vulnerability, identified as CWE‑434, enables attackers to compromise the confidentiality, integrity, and availability of the system and any data processed by it. The impact is remote code execution on the host running the application, potentially exposing sensitive control data and allowing full system takeover.
Affected Systems
The affected product is the Smart Park Management System version 2.0 from the manufacturer known as "ICS‑Park". The system is typically deployed by municipal or transportation authorities to monitor and control parking facilities. No additional vendor or product versions are listed in the CNA data, and the references suggest the software is deployed in public park operations.
Risk and Exploitability
The vulnerability appears to be exploitable via the web application's upload interface; an attacker with network connectivity to the application can submit a malicious file unless further access controls or authentication are enforced. Since no CVSS score is provided, the high severity implied by remote code execution and the absence of an available patch suggests a high risk. The EPSS score is not available and the flaw is not yet listed in CISA’s KEV catalog, but the potential impact warrants immediate attention.
OpenCVE Enrichment