logo

CVE-2026-12183: Critical Auth Bypass in Gas Station Automation System

ID: 86d5abc5-97ed-59b2-9e65-199c1c1691d5

STIX ID: report--86d5abc5-97ed-59b2-9e65-199c1c1691d5

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

**Critical authentication bypass (CVE-2026-12183) in BUK TS-G Gas Station Automation System:** versions 2.9.1–2.10.2 on Linux contain a flaw where any HTTP POST to /php/ajax-login.php returns userid=1 (administrator), allowing unauthenticated full administrative access to fuel dispensing and station management functions; the advisory includes technical analysis, exploitation steps, impact assessment on ICS/OT operations, detection indicators, and immediate remediation guidance including network isolation and vendor contact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.