Executive brief
Aida Computer Information Technology's Hotel Guest Hotspot, a system used to manage internet access for hotel guests, contains a security flaw that allows unauthorized database access. An attacker with basic network access can exploit this to view, modify, or delete sensitive guest information and system data. This could lead to significant data breaches, loss of guest privacy, and disruption of hotel internet services.
Technical details
An SQL injection vulnerability exists in Aida Computer Information Technology Inc. Hotel Guest Hotspot through version 22012026. The flaw stems from improper neutralization of special elements used in SQL commands, allowing an attacker to inject malicious queries. While the attack requires low-level authentication (PR:L), it can be executed over the network without user interaction. Successful exploitation allows for full access to the underlying database, enabling the attacker to read sensitive records, modify data, or potentially gain administrative control over the hotspot management system. As of the disclosure date, the vendor has not responded to reports or provided a patch.
Affected products
- Aida Computer Information Technology Inc. Hotel Guest Hotspot through 22012026
Timeline
- 2026-01-22: disclosed: Initial disclosure by TR-CERT (USOM)
- 2026-01-22: advisory: CVE-2025-4764 published