Amttgroup's vulnerability profile centers on a narrowly scoped but prominently affected product line within the healthcare and institutional sectors, where its HIBOS platform appears as a recurring target. The vendor's disclosures skew strongly toward critical-severity outcomes and cluster around injection-class vulnerabilities—SQL injection, command injection, OS command injection, and cross-site scripting—that reflect the web-facing and system-integration demands of that application. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amttgroup over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-15048CRITICAL AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endpoint. The application construct | Oct 22, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-13123CRITICAL A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation o | Nov 13, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-12253CRITICAL A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/portal/get_expiredtime.php | Oct 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-2701CRITICAL A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the file /manager/network/port_setup | Mar 24, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-6647CRITICAL A vulnerability, which was classified as critical, has been found in AMTT HiBOS 1.0. Affected by this issue is some unknown functionality. The manipulation of the argument Type lea | Dec 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-41476CRITICAL AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php. | Aug 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2025-3983HIGH A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /mana | Apr 27, 2025 | 7.2 | 25 | NO | NO |
CVE-2025-14090HIGH A security flaw has been discovered in AMTT Hotel Broadband Operation System 1.0. This affects an unknown part of the file /manager/card/cardmake_down.php. Performing manipulation | Dec 5, 2025 | 7.2 | 24 | NO | NO |
CVE-2024-11051HIGH A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204. It has been classified as critical. Affected is an unknown function of the file /manager/fron | Nov 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-11050MEDIUM A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /languag | Nov 10, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amttgroup.
Media articles that mention a CVE ID that affects a product developed by Amttgroup — matched by CVE ID, not by vendor name.