Junglewise Threat Intelligence

CVE-2025-0616: Teknolojik Center B2B Netsis Panel SQL injection

CVE-2025-0616 · Severity: high · CVSS 8.2 · Published 2025-10-03

Executive brief

A security vulnerability exists in the Netsis Panel, a business-to-business (B2B) portal used for commercial operations and data management. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive customer information or business records. This issue is particularly serious because the vendor has not responded to security notifications, and no official patch is currently available.

Technical details

The B2B - Netsis Panel suffers from an SQL Injection vulnerability (CWE-89) due to improper neutralization of special elements in SQL commands. This flaw allows a remote, unauthenticated attacker to execute arbitrary SQL queries against the backend database via the network. Successful exploitation can lead to high confidentiality impact and low integrity impact, as indicated by the CVSS score of 8.2. As of the disclosure date, the vendor has not responded to reports, and the vulnerability remains unpatched in versions through 20251003.

Affected products

  • Teknolojik Center Telecommunication Industry Trade Co. Ltd. B2B - Netsis Panel through 20251003

Timeline

  • 2025-10-03: advisory: Initial disclosure by TR-CERT (USOM)
  • 2025-10-03: disclosed: Public disclosure of the vulnerability

References