Unrestricted File Upload in fcba_zzm SMPS 2.0 via FileUploadUtils.java
CVE-2025-10398 Published on September 14, 2025
fcba_zzm ics-park Smart Park Management System FileUploadUtils.java unrestricted upload
A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects unknown code of the file FileUploadUtils.java. The manipulation of the argument File results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Types
What is an Unrestricted File Upload Vulnerability?
The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
CVE-2025-10398 has been classified to as an Unrestricted File Upload vulnerability or weakness.
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2025-10398 has been classified to as an Authorization vulnerability or weakness.
Affected Versions
fcba_zzm ics-park Smart Park Management System Version 2.0 is affected by CVE-2025-10398Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.