Junglewise Threat Intelligence

CVE-2026-8402: Eksagate SYSGUARD 6001 Blind SQL injection

CVE-2026-8402 · Severity: critical · CVSS 9.8 · Published 2026-06-30

Executive brief

A critical security vulnerability has been identified in the Eksagate SYSGUARD 6001, a device used for environmental monitoring and security management. An attacker can remotely manipulate the system's database, potentially leading to the theft of sensitive information, unauthorized access, or complete loss of system control. The manufacturer has stated that this product is no longer supported, meaning no official security patches will be released to fix this issue.

Technical details

A Blind SQL Injection vulnerability exists in Eksagate SYSGUARD 6001 due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send crafted SQL queries to the application, enabling them to infer data from the database or potentially gain administrative access. The vulnerability affects versions 2.0.2 through 6.1.16.0. As the vendor has confirmed the product is end-of-life and unsupported, no patch is available, and users are advised to decommission affected devices or implement strict network segmentation.

Affected products

  • Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 2.0.2 to 6.1.16.0

Timeline

  • 2026-06-30: advisory: NVD publication date

References

Related threats