Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 07 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bukts
Bukts buk Ts-g Gas Station Automation System Linux Linux linux Kernel |
|
| CPEs | cpe:2.3:a:bukts:buk_ts-g_gas_station_automation_system:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Bukts
Bukts buk Ts-g Gas Station Automation System Linux Linux linux Kernel |
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nefteprodukttekhnika Llc
Nefteprodukttekhnika Llc buk Ts-g Gas Station Automation System |
|
| Vendors & Products |
Nefteprodukttekhnika Llc
Nefteprodukttekhnika Llc buk Ts-g Gas Station Automation System |
Tue, 10 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection (CWE-89) in the system configuration module in Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux allows remote attackers to execute arbitrary SQL commands and potentially achieve remote code execution via specially crafted SQL requests. | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution. |
| Metrics |
cvssV2_0
|
cvssV4_0
|
Tue, 10 Mar 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection (CWE-89) in the system configuration module in Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux allows remote attackers to execute arbitrary SQL commands and potentially achieve remote code execution via specially crafted SQL requests. | |
| Title | SQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-03-10T14:10:41.086Z
Reserved: 2026-03-09T18:20:17.516Z
Link: CVE-2026-3843
Updated: 2026-03-10T13:48:49.936Z
Status : Analyzed
Published: 2026-03-10T18:19:05.287
Modified: 2026-05-07T20:34:27.667
Link: CVE-2026-3843
No data.
OpenCVE Enrichment
Updated: 2026-04-16T10:00:14Z