SQL Injection Vulnerability in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System
CVE-2026-78182
Key Information:
- Vendor
Shenzhen Gongji Technology
- Vendor
- CVE Published:
- 24 August 2026
Badges
What is CVE-2026-78182?
A security flaw has been discovered in the function PlanController.getImmediatePlans of the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System, specifically affecting versions up to 300R004C00B300. This vulnerability allows an attacker to manipulate the order and sort of arguments, leading to a SQL injection attack that could be exploited remotely. The exploit has been publicly disclosed, making the affected product particularly susceptible to attacks. Regular updates and patches are advised to mitigate the risk associated with this vulnerability.
Affected Version(s)
XBROTHER Dynamic Environment Monitoring System
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
