Description
An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. The CVE record marks versions through 22012026 as affected and notes that the vendor did not respond to the coordinated disclosure. NVD scores the issue 8.8 with CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; the original TR-CERT CNA assessment of 8.0 remains preserved on the detail page.
CVSS Vector
NVD assessmentNVD · 8.8 High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV: NetworkAC: LowPR: LowUI: NoneS: UnchangedC: HighI: HighA: High
Original CNA assessmentTR-CERT CNA · 8.0 High
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV: AdjacentAC: LowPR: LowUI: NoneS: UnchangedC: HighI: HighA: High
The showcase uses the NVD score as the primary display for this record. The original CNA assessment is preserved beside it so the different attack-vector assumptions remain explicit.
Disclosure Status
- Affected
- Through 22012026
- Patch status
- No public fix confirmed
- Vendor response
- Vendor contacted; no response recorded
- Primary score source
- NVD
References
- CVE.org Record
- TR-CERT / SSB Coordinated Disclosure Advisory TR-26-0001
- NVD — National Vulnerability Database
- MITRE CVE Entry
Record Verification
CreditThe official CVE record credits Sevban DÖNMEZ as finder
PublishedThe CVE record was published on 2026-01-22
CheckedMetadata last checked against the CVE Services record on 2026-08-26
Disclosure Timeline
2026-01-22Published — TR-CERT published the CVE record with the finder credit and CNA CVSS assessment. Source ↗
2026-03-10NVD enrichment — NVD added its independent network-reachability assessment and affected product configuration. Source ↗
2026-06-05Record update — TR-CERT updated the public record and added the current SSB advisory reference. Source ↗
2026-08-26Site verification — jankesec rechecked the public metadata, score provenance, credit, and advisory links.
