CVE-2026-3843 identifies a critical SQL Injection vulnerability (CWE-89) in the Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux. A remote attacker can exploit this flaw by sending specially crafted HTTP POST requests to the /php/request.php endpoint, enabling arbitrary SQL command execution and potential remote code execution. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network attack vector and low attack complexity, allowing for complete compromise of confidentiality, integrity, and availability. Currently, there is no indication of active exploitation, public exploit code is unavailable, and community discussion surrounding this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.9.1, < 2.10.2CPE matchmatch criteria | cpe:2.3:a:bukts:buk_ts-g_gas_station_automation_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.