CVE-2025-4764

HIGH

Aida Computer Information Technology Inc. Hotel Guest Hotspot <2201...

Title source: llm
STIX 2.1

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. This issue affects Hotel Guest Hotspot: through 22012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource government-resource broken-link
https://www.usom.gov.tr/bildirim/tr-26-0001

Scores

CVSS v3 8.0
EPSS 0.0044
EPSS Percentile 35.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
aida/hotel_guest_hotspot < 2026-01-22
Aida Computer Information Technology Inc./Hotel Guest Hotspot < 22012026
Published Jan 22, 2026
Tracked Since Feb 18, 2026