📦 Hibos

by Amttgroup

🔍 What is Hibos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2016-15048

CRITICAL CVSS 9.8 Oct 22, 2025

This is an unauthenticated remote command injection vulnerability in AMTT Hotel Broadband Operation System (HiBOS). Attackers can execute arbitrary system commands as the web server user by sending sp...

CVE-2024-41476

CRITICAL CVSS 9.8 Aug 12, 2024

This vulnerability allows attackers to execute arbitrary SQL commands through the /manager/card/card_detail.php endpoint in AMTT Hotel Broadband Operation System (HiBOS). Successful exploitation could...

CVE-2025-12253

HIGH CVSS 7.3 Oct 27, 2025

This CVE describes a SQL injection vulnerability in AMTT Hotel Broadband Operation System 1.0 affecting the /user/portal/get_expiredtime.php endpoint via the uid parameter. Remote attackers can execut...

CVE-2023-6647

HIGH CVSS 7.3 Dec 10, 2023

This critical SQL injection vulnerability in AMTT HiBOS 1.0 allows attackers to manipulate database queries via the Type parameter. Remote attackers can potentially execute arbitrary SQL commands, lea...

CVE-2025-14090

MEDIUM CVSS 4.7 Dec 5, 2025

This vulnerability allows remote attackers to execute SQL injection attacks against AMTT Hotel Broadband Operation System 1.0 by manipulating the ID parameter in the /manager/card/cardmake_down.php fi...

CVE-2025-13123

MEDIUM CVSS 6.3 Nov 13, 2025

This CVE describes a SQL injection vulnerability in AMTT Hotel Broadband Operation System 1.0. Attackers can remotely exploit the /user/portal/get_firstdate.php endpoint by manipulating the uid parame...

CVE-2025-2701

MEDIUM CVSS 6.3 Mar 24, 2025

This critical vulnerability in AMTT Hotel Broadband Operation System 1.0 allows remote attackers to execute arbitrary operating system commands via command injection in the port_setup.php file. Attack...

CVE-2024-11051

MEDIUM CVSS 6.3 Nov 10, 2024

This critical SQL injection vulnerability in AMTT Hotel Broadband Operation System allows attackers to manipulate database queries via the AccountID parameter in the online_status.php file. Attackers ...