---
id: CVE-2025-15235
title: >-
  QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing
  Authorization vulnerability, allowing authenticated remote attackers to modify
  specific network packet parameters, enabling certain system functions to
  access …
summary: >-
  QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing
  Authorization vulnerability, allowing authenticated remote attackers to modify
  specific network packet parameters, enabling certain system functions to
  access …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: quantatw
product: qoca_aim
affected:
  - qoca_aim < 2.7.6
patched:
  - qoca_aim 2.7.6
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15235'
references:
  - url: 'https://www.twcert.org.tw/en/cp-139-10616-cd942-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-10615-157a3-1.html'
    label: twcert@cert.org.tw
tags:
  - nvd
epss: 0.00295
epssPercentile: 0.19987
ingestedAt: '2026-09-30T23:29:32.533Z'
---

## Overview

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files.

## Affected

- `qoca_aim < 2.7.6`

## Remediation

Upgrade past the affected range:

- `qoca_aim 2.7.6`
