Executive brief
Akmer Informatics TeknoPass, an automation and access control solution, contains a critical security flaw that allows unauthorized individuals to bypass security checks. By manipulating database identifiers, an attacker can gain full access to the system without a valid username or password. This could lead to the theft of sensitive data, unauthorized entry, or a complete shutdown of the automation services.
Technical details
A critical vulnerability exists in Akmer Informatics TeknoPass (versions 20210501 through 20260429) classified as SQL Injection (CWE-89). The flaw stems from the application allowing user-controlled input to influence SQL primary key queries without proper neutralization. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to bypass authorization mechanisms. Successful exploitation grants the attacker full access to the underlying database, potentially leading to complete system compromise, data exfiltration, and loss of integrity.
Affected products
- Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass 20210501 through 20260429
Timeline
- 2026-06-04: disclosed: Initial disclosure by TR-CERT
- 2026-06-04: advisory: NVD publication date