Description
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.
Published: 2026-06-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides within the system configuration module of the Nefteprodukttekhnika BUK TS‑G Gas Station Automation System running on Linux. The module implements an improper authentication check (CWE‑287) that accepts any credentials, effectively bypassing user verification. This flaw allows an attacker to gain unauthorized administrative access and subsequently manipulate core functions of the gas station automation, potentially interfering with fuel dispensing, pricing, and monetary transactions.

Affected Systems

Affected are Linux installations of the BUK TS‑G Gas Station Automation System from version 2.9.1 through 2.10.2. The control of these versions is commonly deployed at fuel dispensing establishments. The vulnerability is specific to the mentioned versions and does not affect earlier releases.

Risk and Exploitability

The CVSS score of 9.3 reflects a severe impact with high potential for full system compromise. The EPSS score is <1%, indicating a low probability of exploitation in the broader threat landscape, yet the flaw is trivial to exploit once the target is identified because it requires only a simple HTTP request containing arbitrary credentials to the system’s authentication interface. The system is not listed in the CISA KEV catalog, so no known exploitation campaigns exist, but the straightforward attack vector may attract threat actors who can use the bypass to gain unwanted administrative control over the gas station’s operations, including dispensing, transaction processing, and safety monitoring.

Generated by OpenCVE AI on August 10, 2026 at 23:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BUK TS‑G Gas Station Automation System to a version that resolves the authentication flaw.
  • Restrict network access to the system’s authentication and privileged management endpoints, allowing only trusted internal devices.
  • Enforce proper session validation and role‑based access controls for all administrative functions, ensuring that only authenticated sessions can perform configuration or control actions.
  • Conduct regular penetration tests and security reviews to verify that authentication checks are correctly implemented and no residual access holes remain.

Generated by OpenCVE AI on August 10, 2026 at 23:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login=<any_value>&pwd=<any_value>), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a server-side session. A remote unauthenticated attacker can invoke any administrative action exposed by the configuration module, including reading and modifying user rules, fuel tank gauges, fuel dispensers, relays, cash registers, bank terminals, fuel cards, price and customer displays, cash collection, and pricing rules. Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.
Title Nefteprodukttekhnika BUK TS-G Gas Station Automation System - Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials

Mon, 10 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials Nefteprodukttekhnika BUK TS-G Gas Station Automation System - Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials

Wed, 05 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Admin Access in Gas Station Automation System Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials

Fri, 26 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Nefteprodukttekhnika Llc
Nefteprodukttekhnika Llc buk Ts-g Gas Station Automation System
Vendors & Products Nefteprodukttekhnika Llc
Nefteprodukttekhnika Llc buk Ts-g Gas Station Automation System

Mon, 15 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 13 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Admin Access in Gas Station Automation System

Sat, 13 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login=<any_value>&pwd=<any_value>), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a server-side session. A remote unauthenticated attacker can invoke any administrative action exposed by the configuration module, including reading and modifying user rules, fuel tank gauges, fuel dispensers, relays, cash registers, bank terminals, fuel cards, price and customer displays, cash collection, and pricing rules.
Weaknesses CWE-287
CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Nefteprodukttekhnika Llc Buk Ts-g Gas Station Automation System
cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published:

Updated: 2026-08-10T11:43:25.169Z

Reserved: 2026-06-13T16:39:43.046Z

Link: CVE-2026-12183

cve-icon Vulnrichment

Updated: 2026-06-15T17:16:54.336Z

cve-icon NVD

Status : Deferred

Published: 2026-06-13T18:16:22.310

Modified: 2026-08-10T12:17:13.967

Link: CVE-2026-12183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T00:00:08Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function