← Terug naar overzicht

A SQL injection vulnerability has been identified in the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System, affecting versions up to 300R004C00B300. The vulnerability exists in the PlanController.getImmediatePlans function within the /xbreport/api/v1/plamange/plansImmediate endpoint. Attackers can manipulate the 'order' or 'sort' arguments to perform SQL injection attacks remotely. The exploit has been publicly disclosed, increasing the risk of active exploitation. No authentication barrier details are specified, suggesting potential unauthenticated remote access. The vulnerability poses a significant risk to organizations using this environmental monitoring system. Public disclosure of the exploit raises the urgency for patching or mitigating the affected systems.

Affected products

  • Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System 300R004C00B300

Related CVE's

  • CVE-2026-78182

Categories

  • Critical Infrastructure
  • Database & Storage
  • Web Technologies