Executive brief
Armiya's Access Control System is software used to manage physical or logical access to secured facilities and resources. An SQL injection vulnerability allows unauthenticated attackers to bypass authentication, extract sensitive data (employee records, access logs, credentials), or modify access permissions, potentially enabling unauthorized facility entry or system takeover.
Technical details
The vulnerability is an SQL injection flaw in the Access Control System that results from improper neutralization of special characters in SQL commands. An attacker can inject malicious SQL syntax through input fields to manipulate database queries. The flaw is network-reachable and does not require authentication or user interaction, making it trivial to exploit. Successful exploitation grants an attacker database-level access, enabling data theft, authentication bypass, and system compromise. The vendor has released a patch in Version 2 and later.
Affected products
- Armiya Information Technologies Ltd. Access Control System before Version 2
Timeline
- 2026-09-10: disclosed