PatchSiren

Nefteprodukttekhnika LLC CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Nefteprodukttekhnika LLC CVE published 2026-03-10

CVE-2026-3843

The BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) that allows remote attackers to execute arbitrary SQL commands via HTTP POST requests to /php/request.php. This vulnerability has a CVSS score of 9.3 and is considered Critical. Organizations using this system should prioritize patching or implementing compensating controls. The CVE record was publish [truncated]