Executive brief
Shenzhen Gongji Technology XBROTHER is an environment monitoring system used for real-time facility and infrastructure oversight. A SQL injection vulnerability in the plan management API allows remote attackers to execute arbitrary database commands without authentication, potentially exposing sensitive environmental data, operational schedules, and system configuration.
Technical details
The vulnerability is a SQL injection flaw in the PlanController.getImmediatePlans function within the /xbreport/api/v1/plamange/plansImmediate endpoint. The vulnerable parameter is the "order/sort" argument, which is not properly sanitized before being used in database queries. The attack is remotely exploitable without requiring authentication or user interaction. An attacker can manipulate the sort parameter to inject malicious SQL commands, leading to unauthorized data access, modification, or deletion. The exploit has been publicly disclosed; patch availability and version information beyond "up to 300R004C00B300" are not documented in available advisories.
Affected products
- Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300
Timeline
- 2026-08-24: disclosed
- other: Exploit publicly disclosed and may be actively used