CVE-2026-3843
EUVD-2026-1049210.03.2026, 18:19
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bukts | buk_ts-g_gas_station_automation_system | 2.9.1 ≤ 𝑥 < 2.10.2 |
𝑥
= Vulnerable software versions