A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12430 A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 17 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Amttgroup hibos
CPEs cpe:2.3:a:amttgroup:hotel_broadband_operating_system:1.0:*:*:*:*:*:*:* cpe:2.3:a:amttgroup:hibos:1.0:*:*:*:*:*:*:*
Vendors & Products Amttgroup hotel Broadband Operating System
Amttgroup hibos

Mon, 12 May 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Amttgroup
Amttgroup hotel Broadband Operating System
CPEs cpe:2.3:a:amttgroup:hotel_broadband_operating_system:1.0:*:*:*:*:*:*:*
Vendors & Products Amttgroup
Amttgroup hotel Broadband Operating System

Mon, 28 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 27 Apr 2025 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
Title AMTT Hotel Broadband Operation System nlog_down.php command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-05-02T04:37:09.714Z

Reserved: 2025-04-26T07:58:42.589Z

Link: CVE-2025-3983

cve-icon Vulnrichment

Updated: 2025-04-28T18:03:43.116Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-27T20:15:15.350

Modified: 2025-10-17T17:13:24.530

Link: CVE-2025-3983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.