---
id: CVE-2016-20096
title: Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp
summary: >-
  Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated
  SQL injection vulnerability that allows remote attackers to execute arbitrary
  SQL commands by manipulating the name parameter in a POST request to the login
  e…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-89
vendor: 'Kunshi Network Technology Co., Ltd.'
product: Linknat VOS3000
affected:
  - linknat_vos3000 2.1.1.5
  - linknat_vos3000 2.1.1.8
  - linknat_vos3000 2.1.2.0
  - linknat_vos2009 2.1.1.5
  - linknat_vos2009 2.1.1.8
  - linknat_vos2009 2.1.2.0
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-07-22T19:03:38.690246Z'
exploitAvailable: true
published: '2026-07-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:13.596Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2016-20096'
references:
  - url: >-
      https://web.archive.org/web/20160601102456/http://www.wooyun.org/bugs/wooyun-2010-0145458
    label: Archived WooYun Disclosure
  - url: 'https://packetstorm.news/files/id/137159'
    label: Packet Storm Entry (137159)
  - url: 'https://www.linknat.com/'
    label: Vendor Homepage
  - url: >-
      https://www.vulncheck.com/advisories/linknat-vos3000-vos2009-sql-injection-via-login-jsp
tags:
  - cve.org
  - exploit-available
epss: 0.00673
epssPercentile: 0.49939
ingestedAt: '2026-09-24T15:45:56.736Z'
---

## Overview

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.

## Affected

- `linknat_vos3000 2.1.1.5`
- `linknat_vos3000 2.1.1.8`
- `linknat_vos3000 2.1.2.0`
- `linknat_vos2009 2.1.1.5`
- `linknat_vos2009 2.1.1.8`
- `linknat_vos2009 2.1.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
