Impact
A classic SQL injection flaw exists in Turkhotspot 5651 Loglama due to lack of proper input sanitization. An attacker capable of inserting malicious SQL code can read, modify, and delete data from the underlying database, potentially compromising sensitive configuration, user, or network traffic information. While the description does not specifically mention code execution, the nature of the vulnerability permits full control over database queries, which can lead to integrity and confidentiality breaches.
Affected Systems
Turkmesh Communication Services Inc. product Turkhotspot 5651 Loglama is affected, specifically versions 5.1.2 and earlier. Any deployment running these versions is vulnerable and should be updated to 5.1.3 or later to receive the fix.
Risk and Exploitability
The CVSS score of 9.8 categorizes this issue as critical. The EPSS score indicates a very low probability of exploitation at the time of assessment, yet the high impact means it should not be ignored. The vulnerability is likely exploitable remotely through exposed interfaces such as web or API endpoints, but no specific attack vector was detailed in the advisory, so the assumption is that an attacker who can submit requests to the affected component could trigger the flaw. No CISA KEV listing suggests that known exploits are not yet widespread, but the potential for data loss remains significant.
OpenCVE Enrichment