Executive brief
Nemon Trade Energy and Trade Energy CRM, software suites used by electricity and gas suppliers, contained a critical security flaw in their login system. An attacker could bypass security controls to access the underlying database without needing a username or password. This could allow unauthorized individuals to steal customer data, create fake administrative accounts, or disrupt the company's operations.
Technical details
A SQL injection vulnerability exists in Nemon Trade Energy and Trade Energy CRM version 2.95.55. The flaw is located in the 'two_steps_auth_code' parameter processed by the 'twoStepsAuthVerification' function at the '/user-login' endpoint. Because the 2FA functionality is accessible without prior authentication, a remote attacker can send crafted requests to execute arbitrary SQL commands. This can lead to full database enumeration, unauthorized creation of privileged users, data modification, or denial-of-service. The vendor has patched this in their SaaS environment as of May 26, 2026.
Affected products
- Nemon Trade Energy 2.95.55
- Nemon Trade Energy CRM 2.95.55
Timeline
- 2026-05-26: patched: The vulnerability was mitigated centrally by the vendor.
- 2026-06-08: advisory: Initial advisory published by INCIBE.
- 2026-06-09: disclosed: CVE-2026-10731 published to NVD.