Junglewise Threat Intelligence

CVE-2026-18210: TRtek Products Store SQL injection

CVE-2026-18210 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Executive brief

TRtek Products Store is an e-commerce platform used to sell goods and services online. The application contains a SQL injection vulnerability that allows attackers to extract, modify, or delete sensitive data from the underlying database, including customer records, payment information, and business data. Exploitation requires only network access and no authentication.

Technical details

The vulnerability is a SQL injection (CWE-89) in TRtek Products Store that arises from improper neutralization of special characters in user input before constructing SQL queries. An attacker can inject arbitrary SQL commands through exposed input parameters, allowing them to read or manipulate database contents. The attack vector is network-based and does not require prior authentication or user interaction. An attacker can execute arbitrary SQL queries to exfiltrate sensitive data, modify records, or potentially achieve remote code execution depending on database permissions. Patching is available in version 030631b2 and later.

Affected products

  • TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products Store before 030631b2

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: advisory: Turkish National Cyber Security Authority advisory

References