CNNVD-202509-1864 Information

CNNVD ID

CNNVD-202509-1864

CVE-2025-10394

  • CNNVD Published: 2025-09-14

Description (Chinese)

fcba_zzm ics-park是fcba_zzm公司的一个智慧园区管理系统。 fcba_zzm ics-park 2.0版本存在代码注入漏洞,该漏洞源于文件ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/JobController.java中未知函数存在缺陷,可能导致远程代码注入攻击。

Description (English)

fcba zzm ics-park is a smart park management system for fcba zzm. Version fcba zzm ics-park 2.0 contains a code-injecting loophole, which stems from deficiencies in unknown functions in document ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/JobController.java, which may lead to a remote code-injection attack.

Hazard Level

High

Vulnerability Type

代码注入

Affected Vendor

fcba_zzm

Published

2025-09-14

Last Modified

2026-02-24

References

https://vuldb.com/?id.323829 https://vuldb.com/?ctiid.323829 https://github.com/Yyjccc/CVE/issues/1 https://vuldb.com/?submit.645729 https://access.redhat.com/security/cve/cve-2025-10394

Share on: