Executive brief
Turkhotspot 5651 Loglama, a logging and hotspot management solution used for regulatory compliance, contains a critical security flaw. An attacker can remotely manipulate the system's database without needing a password. This could lead to the theft of sensitive user logs, unauthorized modification of records, or a complete shutdown of the logging service, potentially resulting in legal non-compliance and data loss.
Technical details
An SQL injection vulnerability exists in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in version 5.1.2 and is addressed in version 5.1.3. The attack vector is network-based and requires no prior authentication or user interaction. Successful exploitation allows a remote attacker to execute arbitrary SQL queries, potentially leading to full database compromise, data exfiltration, and administrative bypass.
Affected products
- Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama 5.1.2 to 5.1.3 (exclusive)
Timeline
- 2026-07-21: advisory: Published by TR-CERT and NVD