THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-3843 (CRITICAL 9.8) — Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in

[NVD] CVE-2026-3843 (CRITICAL 9.8) — Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in

lownvdPublished 2026-03-10

CVE-2026-3843 CVSS: 9.8 CRITICAL Published: 2026-03-10T18:19:05.287

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., acti

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3843