CNNVD-202510-1465 Information

CNNVD ID

CNNVD-202510-1465

CVE-2025-11188

  • CNNVD Published: 2025-10-10

Description (Chinese)

Kiwire Captive Portal是马来西亚Kiwire公司的一个登录认证页面。 Kiwire Captive Portal存在安全漏洞,该漏洞源于nas-id参数存在SQL注入,可能导致数据库被攻击。

Description (English)

Kiwire Captive Portal is a login authentication page for the Malaysian company Kiwire. There is a security loophole in Kiwire Captive Portal, which stems from the SQL injection of the nas-id parameter, which could lead to an attack on the database.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Kiwire

Published

2025-10-10

Last Modified

2026-02-24

References

https://www.synchroweb.com/release-notes/kiwire/security

Patch

https://www.synchroweb.com/release-notes/kiwire/security

Share on: