CVE-2026-12183 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-12183 requires immediate attention.
· 8 min read
Executive Summary
CVE-2026-12183 is a critical authentication bypass in Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux (CVSS 9.8). A remote attacker can post arbitrary credentials to /php/ajax-login.php and receive userid=1 (administrator), then use privileged endpoints under /php/ajax-main.php and /modules/* without a valid server-side session. This means full administrative control of the system configuration module is possible without a password.
No KEV listing and no known in-the-wild exploitation are reported at this time, but the impact is severe enough to treat as an active emergency. For solo developers and small teams, the safest response is to isolate the system immediately, verify exposure, and upgrade or disable the affected module before reconnecting it to any network.
Immediate Action
- Isolate the system now. Remove the host from the internet and restrict access to trusted admin IPs/VPN only. If possible, place it behind a firewall rule that blocks all inbound traffic except from a jump host.
- Disable the configuration module or any web admin interface that exposes
/php/ajax-login.php,/php/ajax-main.php, or/modules/*until patched. - Upgrade immediately to a vendor-fixed release if available. If the fixed version is unknown, use the latest vendor advisory or release notes: Vendor advisory / patch notes.
- Rollback only if needed. If the upgrade breaks operations, restore service from a known-good backup taken before exposure, then keep the host isolated until you can patch safely.
- Assume administrative compromise if the service was reachable from untrusted networks. Review changes to users, pricing rules, dispensers, relays, and cash/fuel controls.
Affected Versions
BUK TS-G Gas Station Automation System 2.9.1through2.10.2on Linux — vulnerableBUK TS-G Gas Station Automation System 2.10.3+— safe if confirmed by vendor patch notes (TODO: verify fixed version)BUK TS-G Gas Station Automation Systemon non-Linux platforms — TODO: confirm exposure
Resolution Guide
This issue is not a typical package-manager dependency, so the main fix is to patch the vendor application, disable exposure, and confirm the login endpoint no longer returns administrative access.
# Linux: identify the installed version
grep -R "2\.9\.[1-9]\|2\.10\.[0-2]" /opt /srv /usr/local 2>/dev/null
# Check whether the vulnerable endpoint is reachable locally
curl -i -X POST http://127.0.0.1/php/ajax-login.php \
-d 'action=dologin&login=test&pwd=test'
# If the vendor provides a fixed installer, upgrade in place
sudo systemctl stop buk-tsg # TODO: replace with actual service name
sudo cp -a /opt/buk-tsg /opt/buk-tsg.backup.$(date +%F)
sudo sh ./install-fixed-version.sh # TODO: replace with vendor installer
sudo systemctl start buk-tsg
JavaScript / Python / Java package managers: this product is not normally installed via npm, pip, Maven, or Gradle. If you wrap it in automation, update only your deployment scripts and remove any hardcoded admin credentials or health checks that assume the login endpoint is safe.
# npm / yarn / pnpm: no direct package fix for this vendor product
# Keep deployment tooling updated instead
npm audit
yarn audit
pnpm audit
# pip / pipx
pip list --outdated
pipx list
# Maven / Gradle
mvn -q dependency:tree
./gradlew dependencies
apt/yum: if your organization repackaged the application into an OS package, use your normal update path.
# Debian/Ubuntu
sudo apt update
sudo apt install --only-upgrade buk-tsg # TODO: package name
sudo apt-mark hold buk-tsg # optional, until vendor fix is verified
# RHEL/CentOS/Fedora
sudo yum update buk-tsg # TODO: package name
# or
sudo dnf update buk-tsg
Docker: if you run the system in a container, replace the image tag with a fixed release and redeploy.
docker pull vendor/buk-tsg:TODO_FIXED_VERSION
docker stop buk-tsg
docker rm buk-tsg
docker run -d --name buk-tsg vendor/buk-tsg:TODO_FIXED_VERSION
Hardening example: block the vulnerable module at the reverse proxy or web server until patched.
# Nginx example: deny access to the login and admin endpoints
location = /php/ajax-login.php { deny all; }
location = /php/ajax-main.php { deny all; }
location ^~ /modules/ { deny all; }
Minimal code fix example: the application must validate a real server-side session and reject unauthenticated requests. A secure login handler should never trust a fixed userid=1 response.
// Pseudocode: require a real authenticated session
session_start();
if (empty($_SESSION['user_id']) || !is_int($_SESSION['user_id'])) {
http_response_code(401);
exit('Unauthorized');
}
// Never return admin identity without verifying credentials
if (!password_verify($pwd, $storedHash)) {
http_response_code(403);
exit('Invalid credentials');
}
Detection & Verification
Check version: look for installed release strings in application files, package metadata, or the web UI footer.
# Search for version markers
grep -R "2\.9\.1\|2\.10\.2\|BUK TS-G" /opt /srv /usr/local 2>/dev/null
# If packaged
rpm -qa | grep -i buk
dpkg -l | grep -i buk
Check for exposure: if the endpoint is reachable, the system may be vulnerable.
curl -s -X POST http://TARGET/php/ajax-login.php \
-d 'action=dologin&login=any&pwd=any' | tee /tmp/buk-login.out
grep -E 'userid=1|admin' /tmp/buk-login.out
Verify the fix: the same request should no longer return administrator identity, and privileged endpoints should require a valid session.
# Expect 401/403 or a non-admin response after patching
curl -i -X POST http://TARGET/php/ajax-login.php \
-d 'action=dologin&login=any&pwd=any'
# Confirm admin endpoints are blocked without a session
curl -i http://TARGET/php/ajax-main.php
curl -i http://TARGET/modules/
Dependency auditors: if your team mirrors or wraps the product in automation, run your normal inventory and vulnerability checks to ensure no stale deployment image remains in use.
Risk and Impact
An attacker who reaches the web interface can become administrator without credentials and change core operational settings. That includes fuel tank gauges, dispensers, relays, cash registers, bank terminals, fuel cards, price displays, customer displays, cash collection, and pricing rules.
For a small team, the blast radius can include service disruption, incorrect pricing, loss of telemetry integrity, and unsafe physical operations. Treat any exposed instance as potentially compromised until you have patched it, reviewed configuration changes, and confirmed that no unauthorized administrative actions occurred.