CRITICAL
Nefteprodukttekhnika LLC
CVE published 2026-03-10
CVE-2026-3843
The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) that allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. This vulnerability has a CVSS score of 9.3 and is considered Critical. Organizations using this system should prioritize patching or implementing compensating controls. The CVE record was publish [truncated]