PatchSiren cyber security CVE debrief
CVE-2026-3843 Nefteprodukttekhnika LLC CVE debrief
The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) that allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. This vulnerability has a CVSS score of 9.3 and is considered Critical. Organizations using this system should prioritize patching or implementing compensating controls. The CVE record was published on 2026-03-10T18:19:05.287Z and has not been modified since then.
- Vendor
- Nefteprodukttekhnika LLC
- Product
- BUK TS-G Gas Station Automation System
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-08-10
Who should care
Organizations using BUK TS-G Gas Station Automation System 2.9.1, cybersecurity teams responsible for industrial control systems, IT professionals managing Linux-based systems, and operators of gas station automation systems should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system configurations, restricting access to /php/request.php, and monitoring for suspicious HTTP POST requests. Vulnerability scanning and penetration testing are also recommended to identify potential exposure and validate defenses. Additionally, security teams should prioritize patching or implementing compensating controls to prevent exploitation. IT professionals should verify that their systems are up-to-date and consider implementing additional security measures to protect against potential attacks. Operators of gas station automation systems should also review their system's configuration and ensure that it is properly secured to prevent unauthorized access. By taking these steps, organizations can help prevent potential attacks and minimize the risk of exploitation. Regular review of system configurations and monitoring for suspicious activity can also help identify potential security issues before they become incidents. Overall, a proactive approach to security and vulnerability management is essential to protecting against potential threats and maintaining the security of critical infrastructure. This vulnerability highlights the importance of robust security measures, including regular patching, vulnerability scanning, and penetration testing, to prevent exploitation and protect against potential attacks. By prioritizing security and taking proactive steps to mitigate this vulnerability, organizations can help protect their systems and prevent potential security incidents. Furthermore, it is essential for organizations to stay informed about potential vulnerabilities and take prompt action to address them, as this can help prevent security breaches and minimize the risk of exploitation. Effective communication and collaboration between IT professionals, security teams, and operators of gas station automation systems are also关键
Technical summary
The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data to execute arbitrary SQL commands and potentially achieve remote code execution. This vulnerability has a CVSS score of 9.3 and is considered Critical.
Defensive priority
Critical vulnerability in BUK TS-G Gas Station Automation System 2.9.1, allowing remote SQL injection and potential code execution.
Recommended defensive actions
- Inventory and verify affected BUK TS-G Gas Station Automation System 2.9.1 instances
- Implement compensating controls to restrict access to /php/request.php
- Monitor for suspicious HTTP POST requests
- Apply vendor patches or updates when available
- Consider vulnerability scanning and penetration testing
Evidence notes
The CVE-2026-3843 vulnerability in BUK TS-G Gas Station Automation System 2.9.1 on Linux allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. Evidence from official sources indicates a SQL injection vulnerability (CWE-89) with a CVSS score of 9.3. Limited information available on affected scope and vendor remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3843 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3843
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3843 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3843
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://bdu.fstec.ru/vul/2025-13914
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c - Broken Link
-
Source reference
Unverified legacy reference
URL: https://bukts.ru/repo-bukts-current
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c - Broken Link
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.