Executive brief
The BUK TS-G is a gas station automation system used to manage fuel sales, inventory, and operations at petrol stations. An attacker can remotely inject malicious SQL commands through the web interface to execute arbitrary database queries and potentially gain complete control of the system, leading to theft of transaction data, service disruption, or ransomware deployment.
Technical details
The vulnerability is a SQL injection (CWE-89) in the system configuration module accessible via the /php/request.php endpoint. An unauthenticated remote attacker can send HTTP POST requests with specially crafted SQL commands in the 'sql' parameter (e.g., action=do&sql=<query_here>&reload_driver=0) using application/x-www-form-urlencoded encoding to execute arbitrary SQL statements against the backend database. Successful exploitation allows an attacker to read, modify, or delete database records, potentially escalate to remote code execution depending on database permissions and the underlying system configuration. The vulnerability affects BUK TS-G 2.9.1 running on Linux; patch status should be verified with the vendor.
Affected products
- Nefteprodukttekhnika BUK TS-G 2.9.1
Timeline
- 2026-03-10: disclosed: CVE-2026-3843 published
- 2025-11: other: Vulnerability likely existed in earlier versions; repository data shows active development