CVE-2025-4764
HIGHAida Computer Information Technology Inc. Hotel Guest Hotspot <2201...
Title source: llmDescription
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource government-resource
broken-link
https://www.usom.gov.tr/bildirim/tr-26-0001
Government Resource government-resource
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0001
Scores
CVSS v3
8.0
EPSS
0.0044
EPSS Percentile
35.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (2)
aida/hotel_guest_hotspot
< 2026-01-22
Aida Computer Information Technology Inc./Hotel Guest Hotspot
< 22012026
Published
Jan 22, 2026
Tracked Since
Feb 18, 2026