Junglewise Threat Intelligence

CVE-2026-12183: Nefteprodukttekhnika BUK TS-G improper authentication in configuration module

CVE-2026-12183 · Severity: critical · CVSS 9.8 · Published 2026-06-13

Executive brief

The BUK TS-G system, used to automate gas station operations, contains a critical security flaw that allows anyone to log in as an administrator without a valid password. An attacker could remotely take control of the station's infrastructure, including fuel dispensers, tank gauges, and payment terminals. This could lead to fuel theft, financial loss, or significant operational disruption.

Technical details

An improper authentication vulnerability (CWE-287) exists in the system configuration module of BUK TS-G. The '/php/ajax-login.php' endpoint incorrectly validates credentials, returning 'userid=1' (administrator) for any HTTP POST request regardless of the password provided. Furthermore, subsequent privileged endpoints under '/php/ajax-main.php' and '/modules/*' fail to perform server-side session validation. A remote, unauthenticated attacker can exploit this to perform administrative actions, including modifying pricing rules, controlling fuel dispensers, and accessing sensitive financial data from bank terminals and cash registers.

Affected products

  • Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2

Timeline

  • 2026-06-13: disclosed
  • 2026-06-13: advisory

References