Executive brief
Armiya's Access Control System is widely deployed to manage physical and logical access to secure facilities. An open redirect flaw allows attackers to craft malicious links that deceive users into visiting attacker-controlled websites, potentially leading to credential theft, malware distribution, or social engineering attacks against facility operators and administrators.
Technical details
The Access Control System contains a URL redirection vulnerability (open redirect) that fails to properly validate redirect destinations before redirecting users. An attacker can craft a specially formed URL with an untrusted destination parameter that, when clicked by a victim, silently redirects them to an attacker-controlled site. No authentication or special privileges are required to exploit this vulnerability—any user clicking a malicious link is at risk. This enables credential harvesting, phishing, and malware distribution campaigns targeting facility access personnel.
Affected products
- Armiya Information Technologies Ltd. Co. Access Control System before version 2
Timeline
- 2026-09-10: disclosed