Description
A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the file /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx. The manipulation of the argument PGUID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Now
AI Analysis

Impact

The vulnerability allows an attacker to inject arbitrary SQL by manipulating the PGUID parameter in the AsyncTreeProxy.aspx component. This flaw combines issues with missing input validation (CWE-74) and lack of proper parameterization (CWE-89). An attacker who successfully exploits the flaw can retrieve, modify, or delete data stored in the underlying database, potentially leading to privacy breaches or corruption of critical operational data.

Affected Systems

Sciyon Koyuan Thermoelectricity Heat Network Management System version 3.0 contains the affected file path /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx. No additional sub-component or patch level details are documented, and the vendor has not released an official fix according to the available information.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker could likely launch the attack remotely via the web interface, provided the target system is exposed to the public or an untrusted internal network.

Generated by OpenCVE AI on April 17, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the vendor’s security patch or upgrade to a newer, non‑vulnerable release as soon as it becomes available.
  • Restrict or block external access to the /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx endpoint for non‑authorized users.
  • Implement strict input validation and parameterization for the PGUID field to eliminate injection vectors, addressing CWE‑74 and CWE‑89 weaknesses.
  • Monitor database query logs for anomalous or unauthorized statements that may indicate ongoing injection attempts.

Generated by OpenCVE AI on April 17, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 18 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sciyon
Sciyon koyuan Thermoelectricity Heat Network Management System
Vendors & Products Sciyon
Sciyon koyuan Thermoelectricity Heat Network Management System

Tue, 17 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the file /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx. The manipulation of the argument PGUID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Sciyon Koyuan Thermoelectricity Heat Network Management System AsyncTreeProxy.aspx sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sciyon Koyuan Thermoelectricity Heat Network Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T10:14:28.207Z

Reserved: 2026-02-17T09:19:59.421Z

Link: CVE-2026-2621

cve-icon Vulnrichment

Updated: 2026-02-17T21:07:44.979Z

cve-icon NVD

Status : Deferred

Published: 2026-02-17T21:22:16.633

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-2621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T19:00:11Z

Weaknesses