PT-2025-16202 · Wowjoy 浙江湖州华卓信息科技有限公司 · Internet Doctor Workstation System

Hnsjwaxxjsyxgs

·

Published

2025-04-14

·

Updated

2025-04-14

·

CVE-2025-3550

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System version 1.0
Description: A vulnerability has been found in the Internet Doctor Workstation System, affecting an unknown functionality of the file "/v1/pushConfig/detail/". The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations: For version 1.0, as a temporary workaround, consider restricting access to the "/v1/pushConfig/detail/" endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-3550

Affected Products

Internet Doctor Workstation System