Description
A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XForm/BM/BusComManagement/TireMng.aspx. Executing a manipulation of the argument key can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-01-26
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Assess Impact
AI Analysis

Impact

The flaw resides in the Page_Load routine of TireMng.aspx within the Hisense TransTech Smart Bus Management System. An attacker can manipulate the 'key' argument to inject arbitrary SQL statements, thereby gaining unauthorized access to, or alteration of, the underlying database. The vulnerability enables remote exploitation, as confirmed by published proofs of concept, and carries the potential to compromise data confidentiality and integrity across the bus management platform.

Affected Systems

Hisense TransTech Smart Bus Management System versions up to and including 20260113 are affected. The vulnerability is present in the TireMng.aspx component under the YZSoft/Forms/XForm/BM/BusComManagement directory. No later versions were listed, so the stated release date marks the highest known vulnerable build.

Risk and Exploitability

The CVSS score of 6.9 reflects a high severity rating for this SQL injection. EPSS is reported to be below 1%, indicating a very low but non-zero probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, suggesting it has not yet been linked to known large-scale attacks. The attack vector is remote; an adversary only needs to influence the 'key' parameter sent to the web server. The existence of a publicly disclosed exploit demonstrates that the flaw can be leveraged with minimal technical skill.

Generated by OpenCVE AI on April 18, 2026 at 02:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's official patch as soon as it becomes available.
  • Enforce strict input validation on the 'key' parameter, ensuring only expected values are accepted and using parameterized queries to prevent SQL injection.
  • Restrict external access to the Bus Management System by placing it behind a network perimeter, applying firewall rules, and monitoring for anomalous query activity.

Generated by OpenCVE AI on April 18, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 27 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Hisense
Hisense smart Bus Management System
Vendors & Products Hisense
Hisense smart Bus Management System

Mon, 26 Jan 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XForm/BM/BusComManagement/TireMng.aspx. Executing a manipulation of the argument key can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Hisense TransTech Smart Bus Management System TireMng.aspx Page_Load sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Hisense Smart Bus Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:59:17.016Z

Reserved: 2026-01-26T17:44:41.113Z

Link: CVE-2026-1449

cve-icon Vulnrichment

Updated: 2026-01-27T21:27:25.750Z

cve-icon NVD

Status : Deferred

Published: 2026-01-27T00:15:50.790

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T02:45:27Z

Weaknesses