PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3843 Nefteprodukttekhnika LLC CVE debrief

The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) that allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. This vulnerability has a CVSS score of 9.3 and is considered Critical. Organizations using this system should prioritize patching or implementing compensating controls. The CVE record was published on 2026-03-10T18:19:05.287Z and has not been modified since then.

Vendor
Nefteprodukttekhnika LLC
Product
BUK TS-G Gas Station Automation System
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-08-10
Advisory published
2026-03-10
Advisory updated
2026-08-10

Who should care

Organizations using BUK TS-G Gas Station Automation System 2.9.1, cybersecurity teams responsible for industrial control systems, IT professionals managing Linux-based systems, and operators of gas station automation systems should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system configurations, restricting access to /php/request.php, and monitoring for suspicious HTTP POST requests. Vulnerability scanning and penetration testing are also recommended to identify potential exposure and validate defenses. Additionally, security teams should prioritize patching or implementing compensating controls to prevent exploitation. IT professionals should verify that their systems are up-to-date and consider implementing additional security measures to protect against potential attacks. Operators of gas station automation systems should also review their system's configuration and ensure that it is properly secured to prevent unauthorized access. By taking these steps, organizations can help prevent potential attacks and minimize the risk of exploitation. Regular review of system configurations and monitoring for suspicious activity can also help identify potential security issues before they become incidents. Overall, a proactive approach to security and vulnerability management is essential to protecting against potential threats and maintaining the security of critical infrastructure. This vulnerability highlights the importance of robust security measures, including regular patching, vulnerability scanning, and penetration testing, to prevent exploitation and protect against potential attacks. By prioritizing security and taking proactive steps to mitigate this vulnerability, organizations can help protect their systems and prevent potential security incidents. Furthermore, it is essential for organizations to stay informed about potential vulnerabilities and take prompt action to address them, as this can help prevent security breaches and minimize the risk of exploitation. Effective communication and collaboration between IT professionals, security teams, and operators of gas station automation systems are also关键

Technical summary

The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data to execute arbitrary SQL commands and potentially achieve remote code execution. This vulnerability has a CVSS score of 9.3 and is considered Critical.

Defensive priority

Critical vulnerability in BUK TS-G Gas Station Automation System 2.9.1, allowing remote SQL injection and potential code execution.

Recommended defensive actions

  • Inventory and verify affected BUK TS-G Gas Station Automation System 2.9.1 instances
  • Implement compensating controls to restrict access to /php/request.php
  • Monitor for suspicious HTTP POST requests
  • Apply vendor patches or updates when available
  • Consider vulnerability scanning and penetration testing

Evidence notes

The CVE-2026-3843 vulnerability in BUK TS-G Gas Station Automation System 2.9.1 on Linux allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. Evidence from official sources indicates a SQL injection vulnerability (CWE-89) with a CVSS score of 9.3. Limited information available on affected scope and vendor remediation.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-10T18:19:05.287Z and has not been modified since then.