CVE-2026-12183

9.8 CRITICAL
Published: June 13, 2026 Modified: June 13, 2026
View on NVD

Description

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login=<any_value>&pwd=<any_value>), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a server-side session. A remote unauthenticated attacker can invoke any administrative action exposed by the configuration module, including reading and modifying user rules, fuel tank gauges, fuel dispensers, relays, cash registers, bank terminals, fuel cards, price and customer displays, cash collection, and pricing rules.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://bukts.ru/repo-bukts-current
Source: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
https://cwe.mitre.org/data/definitions/287.html
Source: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
https://cwe.mitre.org/data/definitions/306.html
Source: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
https://github.com/ciprobe/bukts_auth_bypass
Source: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

4 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)