Executive brief
Aida Computer Information Technology's Hotel Guest Hotspot, a system used to manage internet access for hotel guests, contains a security vulnerability that allows for reflected cross-site scripting. An attacker could use this to execute malicious scripts in the browser of a legitimate user, potentially leading to session hijacking or the theft of sensitive information. The vendor has not responded to reports of this issue, and no official patch is currently available.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Aida Computer Information Technology Inc. Hotel Guest Hotspot through version 22012026. The flaw stems from improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link, causing malicious JavaScript to execute in the context of the user's browser session. This can lead to the disclosure of sensitive session tokens or unauthorized actions on behalf of the user. As of the disclosure date, the vendor has not responded to notifications, and no patch has been confirmed.
Affected products
- Aida Computer Information Technology Inc. Hotel Guest Hotspot through 22012026
Timeline
- 2026-01-22: disclosed: Initial disclosure by TR-CERT/USOM
- 2026-01-22: advisory: NVD publication date