A SQL injection vulnerability has been identified in Shenzhen Gongji Technology's XBROTHER Dynamic Environment Monitoring System, affecting versions up to 300R004C00B300. The vulnerability resides in the PlanController.getImmediatePlans function within the /xbreport/api/v1/plamange/plansImmediate endpoint. Attackers can manipulate the 'order' or 'sort' arguments to perform SQL injection attacks remotely. The exploit has been publicly disclosed, increasing the risk of active exploitation. This affects monitoring infrastructure systems commonly used in data center and facility management environments. No authentication details are specified, suggesting potential unauthenticated access. The public disclosure and remote exploitability make this a high-severity issue requiring prompt patching.