PT-2026-24203 · Nefteprodukttekhnika Llc · Buk Ts-G Gas Station Automation System

Yergashvoyev Jamshed

·

Published

2026-03-10

·

Updated

2026-05-12

·

CVE-2026-3843

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nefteprodukttekhnika BUK TS-G Gas Station Automation System version 2.9.1
Description The system contains a SQL Injection issue in the system configuration module. An attacker can send crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query here>&reload driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /php/request.php endpoint.

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-04518
CVE-2026-3843

Affected Products

Buk Ts-G Gas Station Automation System