CHT Security Team Discovered a Vulnerability in Well-Known Administrative Management Information System

Version:

Version  5.0.98.17

Detail:

An administrative management information system fails to validate certain function parameters, allowing attackers to bypass restrictions and upload a backdoor program, resulting in remote code execution (RCE). This vulnerability can be classified under A01 – Broken Access Control in the OWASP Top 10 (2021).

CHT Security team recommends the following measures:

After receiving the information, the developer has already release relevant updates as soon as possible. If agencies or enterprises use this system, it is recommended to contact the manufacturer as soon as possible for updates.

1. Users: Contact the manufacturer to install the patch as soon as possible.

2. System developers: Input parameters should be checked during program development.

3. System developers: It is recommended to introduce SSDLC (Secure Software Development Life Cycle) conduct secure program development education and training, and regularly perform security tests such as source code review and penetration test to effectively ensure product and user security.

Credits:

YuCheng Lin (CHT Security)

YiuDa Tsai (CHT Security)

ChengWei Tsao (CHT Security)