The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 15 Nov 2025 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
CPEs cpe:2.3:a:synchroweb:kiwire:3.6:*:*:*:*:*:*:*

Mon, 03 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
References

Tue, 21 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Synchroweb
Synchroweb kiwire
Vendors & Products Synchroweb
Synchroweb kiwire

Tue, 14 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 11:15:00 +0000

Type Values Removed Values Added
Description The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.
Title CVE-2025-11188
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-11-03T17:31:39.369Z

Reserved: 2025-09-30T12:21:36.240Z

Link: CVE-2025-11188

cve-icon Vulnrichment

Updated: 2025-11-03T17:31:39.369Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-10T11:15:40.407

Modified: 2025-11-14T23:46:44.703

Link: CVE-2025-11188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-21T13:14:09Z