Executive brief
A vulnerability in the Art-in Wi-Fi Cloud Hotspot system allows unauthorized users to bypass security controls by repeatedly attempting to log in without being blocked. This system is typically used to manage guest Wi-Fi access in public or corporate spaces. An attacker could exploit this to gain unauthorized access to the network or disrupt the service for legitimate users.
Technical details
The Art-in Wi-Fi Cloud Hotspot is vulnerable to CWE-307 (Improper Restriction of Excessive Authentication Attempts). The system does not implement adequate rate limiting or account lockout mechanisms for failed login attempts. A remote, unauthenticated attacker can leverage this to perform brute-force or credential stuffing attacks over the network. Successful exploitation can lead to authentication bypass, unauthorized network access, and potential denial of service (DoS) conditions. The issue is addressed in versions released after May 30, 2025.
Affected products
- Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot before 30.05.2025
Timeline
- 2025-06-24: disclosed
- 2025-05-30: patched