• News/
  • https://www.theregister.com/2024/04/05/hotel_checkin_terminal_bug/

Hotel check-in terminal bug spews out access codes for guest rooms

The Register
·
Connor Jones
·
Published Apr 5, 2024
·
Updated

A self-service check-in terminal used in a German Ibis budget hotel was found leaking hotel room keycodes, and the researcher behind the discovery claims the issue could potentially affect hotels around Europe. The terminal's security flaw could be abused by anyone, requiring no technical knowledge or specialized tooling. Realistically, an attacker could aggregate an array of room keycodes in just a few minutes – as long as it would take a regular customer to use the same machine to check in to their room. Self-service check-in terminals can be used by hotel guests as an alternative to speaking with front desk staff, who sometimes aren't available to serve. As well as allowing guests to check into their rooms, these terminals also offer the capability to search for information about existing bookings. If, for example, a guest forgets their keycode, they can input their booking reference number and the terminal will present details about their booking, including their room code. Martin Schobert at Swiss security firm Pentagrid discovered that an attacker could input a series of six consecutive dashes (------) in place of a booking reference number and the terminal would return an extensive list of room details. "Any other sequence of dashes is accepted if it is long enough to enable the submit button," he said. "Therefore, it is assumed that a variable length string is likely not a master code, but a bug or a not deactivated test function." Once the dashes were entered, the bo...

Read full article

Affected Software

3 affected components
Accor Self-service check-in terminal
dormakaba Saflok MT
dormakaba Saflok RT Plus

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability in a self-service check-in terminal at a German Ibis budget hotel that exposes access codes for guest rooms.

2

What security implications are discussed?

The vulnerability could allow unauthorized individuals to access guest rooms by obtaining key codes, posing a significant risk to hotel security.

3

What products or software are affected?

The affected products include the Accor Self-service check-in terminal and dormakaba's Saflok MT and Saflok RT Plus systems.

4

Who discovered the vulnerability in the hotel check-in terminal?

The vulnerability was discovered by a security researcher who claims it could impact hotels across Europe.

5

What preventative measures can hotels take in response to this discovery?

Hotels should conduct security audits on their check-in systems and update their software to mitigate the risk of unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203