Impact
The vulnerability is a user‑controlled primary key that allows attackers to inject SQL statements, bypassing authorization and gaining access to protected data. This flaw exposes database credentials and sensitive records to unauthenticated users, which could be used for further attacks such as data exfiltration or modification.
Affected Systems
Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass is affected from version 20210501 through 20260429. The product is used across the company’s automation and trade operations and any deployment of these versions is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Attackers can exploit the flaw remotely, likely via the web interface or APIs that accept primary key inputs. Because the EPSS score is unavailable and the vulnerability is not listed in KEV, the current exploitation likelihood is uncertain, but the combination of high severity and wide application range makes it a top priority for remediation.
OpenCVE Enrichment