Executive brief
A security vulnerability in the Turpak Automatic Station Monitoring System, which is used to manage and monitor fuel station operations, allows an attacker to bypass security controls. By manipulating specific data keys, a user with low-level access can gain higher-level administrative privileges. This could lead to unauthorized access to sensitive station data or the ability to modify system configurations.
Technical details
The Turpak Automatic Station Monitoring System is vulnerable to an Authorization Bypass Through User-Controlled Key (CWE-639). The flaw exists in versions prior to 5.0.6.51 and allows an authenticated attacker with low privileges to bypass authorization checks by providing or manipulating a key (such as an ID or parameter) that the application uses to make access control decisions. This results in privilege escalation, potentially allowing the attacker to access data or perform actions belonging to other users or administrators. The attack can be carried out over the network without user interaction. A fix is available in version 5.0.6.51.
Affected products
- Turpak Automatic Station Monitoring System before 5.0.6.51
Timeline
- 2025-07-21: disclosed
- 2025-07-21: advisory