Executive brief
The Bian Que Feijiu Intelligent Emergency and Quality Control System, a platform used for managing emergency medical services and patient data, contains a security flaw that allows unauthorized access to its database. An attacker can exploit this to steal sensitive medical records, bypass login security, or potentially take control of the server. This could lead to significant data breaches and disruption of critical emergency medical operations.
Technical details
An unauthenticated SQL injection vulnerability exists in the 'GetLyfsByParams' endpoint of the Bian Que Feijiu Intelligent Emergency and Quality Control System. The vulnerability is located within the '/AppService/BQMedical/WebServiceForFirstaidApp.asmx' interface and stems from a failure to properly sanitize the 'strOpid' parameter. A remote, unauthenticated attacker can send specially crafted HTTP POST requests containing SQL payloads to the vulnerable endpoint. Successful exploitation allows for arbitrary data exfiltration, authentication bypass, and potentially remote code execution depending on the database's configuration and permissions. Evidence of active exploitation was reported as early as July 2023.
Affected products
- Bian Que Feijiu (IVTBQ) Bian Que Feijiu Intelligent Emergency and Quality Control System Builds prior to June 2025
Timeline
- 2025-06-13: disclosed: Initial public disclosure of the vulnerability by security researchers.
- 2025-07-23: exploited: Exploitation evidence first observed by the Shadowserver Foundation.
- 2025-08-27: advisory: CVE-2025-34162 published.