Executive brief
Doruk Wispotter, a hotspot management and authentication solution, contains a security flaw that fails to limit the number of login attempts. This allows an unauthorized person to repeatedly guess user passwords without being blocked. If successful, an attacker could gain unauthorized access to user accounts or the management interface, potentially compromising user data or network control.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) and CWE-287 (Improper Authentication) within the Doruk Wispotter hotspot management system. The application fails to implement sufficient rate limiting or account lockout mechanisms on its authentication endpoints. A remote, unauthenticated attacker can exploit this by performing automated brute-force or dictionary attacks to identify valid credentials. Successful exploitation allows for unauthorized access to the system, though the reported impact is currently limited to low-level data confidentiality. The issue is addressed in version v2025.10.08.1.
Affected products
- Doruk Communication and Automation Industry and Trade Inc. Wispotter 1.0 before v2025.10.08.1
Timeline
- 2026-02-18: advisory: Initial advisory published by TR-CERT (USOM)
- 2026-02-18: disclosed
- 2025-10-08: patched: Patch released in version v2025.10.08.1