PT-2025-32336 · Wanzhou · Woes Intelligent Optimization Energy Saving System

Cgs1234

·

Published

2025-08-08

·

Updated

2025-08-08

·

CVE-2025-8704

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wanzhou WOES Intelligent Optimization Energy Saving System version 1.0
Description A critical issue exists in the Analysis Conclusion Query Module of Wanzhou WOES Intelligent Optimization Energy Saving System. The vulnerability is due to improper processing of the resultId argument within the /WEAS AlarmResult/GetAlarmResultProcessList endpoint, leading to a SQL injection. This allows for remote manipulation of alarm data, potentially enabling attackers to spoof or silence alarms.
Recommendations Versions prior to 1.0 should be used. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-8704

Affected Products

Woes Intelligent Optimization Energy Saving System