Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection.

This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A classic SQL injection flaw exists in Turkhotspot 5651 Loglama due to lack of proper input sanitization. An attacker capable of inserting malicious SQL code can read, modify, and delete data from the underlying database, potentially compromising sensitive configuration, user, or network traffic information. While the description does not specifically mention code execution, the nature of the vulnerability permits full control over database queries, which can lead to integrity and confidentiality breaches.

Affected Systems

Turkmesh Communication Services Inc. product Turkhotspot 5651 Loglama is affected, specifically versions 5.1.2 and earlier. Any deployment running these versions is vulnerable and should be updated to 5.1.3 or later to receive the fix.

Risk and Exploitability

The CVSS score of 9.8 categorizes this issue as critical. The EPSS score indicates a very low probability of exploitation at the time of assessment, yet the high impact means it should not be ignored. The vulnerability is likely exploitable remotely through exposed interfaces such as web or API endpoints, but no specific attack vector was detailed in the advisory, so the assumption is that an attacker who can submit requests to the affected component could trigger the flaw. No CISA KEV listing suggests that known exploits are not yet widespread, but the potential for data loss remains significant.

Generated by OpenCVE AI on July 30, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-supplied patch or upgrade to version 5.1.3 or later for Turkhotspot 5651 Loglama
  • If a patch is not yet available, restrict external access to the administration or management interfaces that handle user input, effectively limiting the attack surface
  • Implement input validation or a web application firewall rule set to reject or escape characters that could influence SQL queries, mitigating the risk of injection until a patch is applied

Generated by OpenCVE AI on July 30, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Turkmesh Communication Services
Turkmesh Communication Services turkhotspot 5651 Loglama
Vendors & Products Turkmesh Communication Services
Turkmesh Communication Services turkhotspot 5651 Loglama

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.
Title SQLi in Turkmesh's Turkhotspot 5651 Loglama
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Turkmesh Communication Services Turkhotspot 5651 Loglama
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-21T12:13:03.826Z

Reserved: 2026-01-29T13:28:08.249Z

Link: CVE-2026-1617

cve-icon Vulnrichment

Updated: 2026-07-21T12:12:13.046Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')