PatchSiren cyber security CVE debrief
CVE-2026-3843 Nefteprodukttekhnika LLC CVE debrief
The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) that allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. This vulnerability has a CVSS score of 9.3 and is considered Critical. Organizations using this system should prioritize patching or implementing compensating controls. The CVE record was published on 2026-03-10T18:19:05.287Z and has not been modified since then.
- Vendor
- Nefteprodukttekhnika LLC
- Product
- BUK TS-G Gas Station Automation System
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-08-10
Who should care
Organizations using BUK TS-G Gas Station Automation System 2.9.1, cybersecurity teams responsible for industrial control systems, IT professionals managing Linux-based systems, and operators of gas station automation systems should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system configurations, restricting access to /php/request.php, and monitoring for suspicious HTTP POST requests. Vulnerability scanning and penetration testing are also recommended to identify potential exposure and validate defenses. Additionally, security teams should prioritize patching or implementing compensating controls to prevent exploitation. IT professionals should verify that their systems are up-to-date and consider implementing additional security measures to protect against potential attacks. Operators of gas station automation systems should also review their system's configuration and ensure that it is properly secured to prevent unauthorized access. By taking these steps, organizations can help prevent potential attacks and minimize the risk of exploitation. Regular review of system configurations and monitoring for suspicious activity can also help identify potential security issues before they become incidents. Overall, a proactive approach to security and vulnerability management is essential to protecting against potential threats and maintaining the security of critical infrastructure. This vulnerability highlights the importance of robust security measures, including regular patching, vulnerability scanning, and penetration testing, to prevent exploitation and protect against potential attacks. By prioritizing security and taking proactive steps to mitigate this vulnerability, organizations can help protect their systems and prevent potential security incidents. Furthermore, it is essential for organizations to stay informed about potential vulnerabilities and take prompt action to address them, as this can help prevent security breaches and minimize the risk of exploitation. Effective communication and collaboration between IT professionals, security teams, and operators of gas station automation systems are also关键
Technical summary
The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data to execute arbitrary SQL commands and potentially achieve remote code execution. This vulnerability has a CVSS score of 9.3 and is considered Critical.
Defensive priority
Critical vulnerability in BUK TS-G Gas Station Automation System 2.9.1, allowing remote SQL injection and potential code execution.
Recommended defensive actions
- Inventory and verify affected BUK TS-G Gas Station Automation System 2.9.1 instances
- Implement compensating controls to restrict access to /php/request.php
- Monitor for suspicious HTTP POST requests
- Apply vendor patches or updates when available
- Consider vulnerability scanning and penetration testing
Evidence notes
The CVE-2026-3843 vulnerability in BUK TS-G Gas Station Automation System 2.9.1 on Linux allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. Evidence from official sources indicates a SQL injection vulnerability (CWE-89) with a CVSS score of 9.3. Limited information available on affected scope and vendor remediation.
Official resources
-
CVE-2026-3843 CVE record
CVE.org
-
CVE-2026-3843 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c - Broken Link
-
Source reference
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c - Broken Link
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-10T18:19:05.287Z and has not been modified since then.