External risk intelligence

BUK TS-G Gas Station Automation System SQL Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-3843

The vulnerability resides in a gas station automation system. While such systems often operate on internal operational networks, they may have web interfaces exposed to the internet for remote monitoring or management in some deployment configurations, though public internet exposure is not a standard requirement for all installations of this product type.

SQL Injection

Bukts Buk Ts G Gas Station Automation System

2.9.1 to before 2.10.2

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a critical vulnerability found in a gas station automation system that could allow unauthorized access to execute commands remotely. The issue arises from how the system handles data, potentially enabling attackers to manipulate its configuration.

  • System vulnerability allows remote command execution.
  • Critical for operational technology and industrial control systems.
  • Confirm relevance and potential exposure of this system.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted HTTP POST requests to a specific endpoint on the gas station automation system. This requires no special access, and the attacker can craft requests to inject arbitrary SQL commands, potentially leading to remote code execution.

  • Requires network access.
  • Triggered by sending malicious HTTP requests.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands by sending crafted HTTP POST requests to a specific endpoint. This could lead to the execution of arbitrary code on the affected system, depending on the system's configuration and network exposure.

  • System configuration data at risk.
  • SQL injection via HTTP POST requests.
  • Potential for arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

System owners and application teams are likely responsible for addressing this SQL injection vulnerability in the gas station automation system. The first practical step is to identify all instances of the affected software, determine their network reachability and criticality, and then confirm the accountable owner for each instance to plan remediation.

  • Application owners should be accountable for this issue.
  • Verify system reachability and business criticality.
  • Plan coordinated remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Nefteprodukttekhnika BUK TS-G system?

BUK TS-G is a gas station automation system built on Linux. It manages essential forecourt operations, including fuel dispenser controls, inventory tracking, and payment processing, serving as a centralized management hub for retail fuel environments.

What does CVE-2026-3843 mean for BUK TS-G?

This CVE represents a SQL Injection vulnerability, classified as CWE-89. In simple terms, the system fails to properly filter user-provided data, allowing an attacker to inject their own database commands. This weakness is severe because it can be leveraged to bypass system controls and potentially execute arbitrary code on the underlying server.

How is this SQL injection vulnerability triggered?

An attacker triggers this flaw by sending a specially crafted HTTP POST request to the system's '/php/request.php' endpoint. The request must include a specific SQL parameter to be successful. The vulnerability does not trigger if the application is accessed through methods other than these specific HTTP POST requests.

Is my BUK TS-G system at risk?

Halo Surface Signal indicates the risk depends on your network configuration. While these systems are primarily intended for internal industrial or operational networks, some deployments may have their web interfaces accessible via the internet for remote management, which significantly increases the risk of unauthorized remote access.

What should I do to secure my affected systems?

Your first step is to create a complete inventory of all BUK TS-G deployments within your environment. Once identified, evaluate the network accessibility of each instance to determine if they are reachable from outside your protected perimeter. After assessing risk and business criticality, coordinate with the responsible application owners to prioritize and plan the necessary security updates.

References