Executive brief
Hanwang e-Face General Management Platform, a facial recognition and identity management system, contains a security vulnerability that allows remote attackers to interfere with its database. By sending specially crafted requests, an attacker can perform unauthorized database queries, potentially leading to the exposure of sensitive information or disruption of the management system. This could impact the integrity of identity records and overall facility security operations.
Technical details
A SQL injection vulnerability exists in Hanwang e-Face General Management Platform version 6.3.5.4. The flaw is located within the /sysAuthStr/querySysAuthStr.do component, where improper neutralization of special elements in the 'order' argument allows for the injection of malicious SQL commands. This is a remote, unauthenticated attack vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation could allow an attacker to read, modify, or delete data within the underlying database. Public exploit code is reportedly available.
Affected products
- Hanwang e-Face General Management Platform 6.3.5.4
Timeline
- 2026-07-05: advisory
- 2026-07-05: disclosed