---
id: CVE-2026-3843
title: >-
  Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux
  contains a SQL Injection vulnerability (CWE-89) in the system configuration
  module
summary: >-
  Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux
  contains a SQL Injection vulnerability (CWE-89) in the system configuration
  module. A remote attacker can send specially crafted HTTP POST requests to the
  /php/re…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: bukts
product: buk_ts-g_gas_station_automation_system
affected:
  - 'buk_ts-g_gas_station_automation_system >= 2.9.1, < 2.10.2'
patched:
  - buk_ts-g_gas_station_automation_system 2.10.2
published: '2026-03-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3843'
references:
  - url: 'https://bdu.fstec.ru/vul/2025-13914'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
  - url: 'https://bukts.ru/repo-bukts-current'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
tags:
  - nvd
epss: 0.00763
epssPercentile: 0.53945
ingestedAt: '2026-08-10T12:39:46.175Z'
---

## Overview

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.

## Affected

- `buk_ts-g_gas_station_automation_system >= 2.9.1, < 2.10.2`

## Remediation

Upgrade past the affected range:

- `buk_ts-g_gas_station_automation_system 2.10.2`
