{"id":"CVE-2026-3843","title":"Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module","summary":"Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/re…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"bukts","product":"buk_ts-g_gas_station_automation_system","affected":["buk_ts-g_gas_station_automation_system >= 2.9.1, < 2.10.2"],"patched":["buk_ts-g_gas_station_automation_system 2.10.2"],"published":"2026-03-10","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3843","references":[{"url":"https://bdu.fstec.ru/vul/2025-13914","label":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"},{"url":"https://bukts.ru/repo-bukts-current","label":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"tags":["nvd"],"epss":0.00763,"epssPercentile":0.53909,"ingestedAt":"2026-08-10T12:39:46.175Z","slug":"CVE-2026-3843","body":"## Overview\n\nNefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.\n\n## Affected\n\n- `buk_ts-g_gas_station_automation_system >= 2.9.1, < 2.10.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `buk_ts-g_gas_station_automation_system 2.10.2`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}