Junglewise Threat Intelligence

CVE-2026-1617: Turkmesh Turkhotspot 5651 Loglama SQL injection

CVE-2026-1617 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Executive brief

Turkhotspot 5651 Loglama, a logging and hotspot management solution used for regulatory compliance, contains a critical security flaw. An attacker can remotely manipulate the system's database without needing a password. This could lead to the theft of sensitive user logs, unauthorized modification of records, or a complete shutdown of the logging service, potentially resulting in legal non-compliance and data loss.

Technical details

An SQL injection vulnerability exists in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in version 5.1.2 and is addressed in version 5.1.3. The attack vector is network-based and requires no prior authentication or user interaction. Successful exploitation allows a remote attacker to execute arbitrary SQL queries, potentially leading to full database compromise, data exfiltration, and administrative bypass.

Affected products

  • Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama 5.1.2 to 5.1.3 (exclusive)

Timeline

  • 2026-07-21: advisory: Published by TR-CERT and NVD

References