ZeroHour

CVE-2026-18210

Unauthenticated SQL Injection in TRtek Products's Store

CVSS 3.1
9.8 critical
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-18210 is a critical SQL injection flaw (CWE-89) in the 'Products's Store' software from Turkish vendor TRtek Technological Products, caused by improper neutralization of special elements used in SQL commands. Because the flaw is exploitable over the network without privileges or user interaction (CVSS 3.1 vector AV:N/PR:N/UI:N), an unauthenticated attacker can trigger it with crafted input sent to the application. Successful exploitation could let the attacker read, modify, or disrupt the underlying database, consistent with the high confidentiality, integrity, and availability impacts scored in the CVSS vector. Any deployment of Products's Store running a build before 030631b2 is affected. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.4% probability of exploitation within 30 days, indicating no confirmed exploitation at this time.

What to do: Deployments should update Products's Store to build 030631b2 or later; because the fixed identifier appears to be a commit/build reference rather than a release number, verify with the vendor or the USOM advisory which shipped version contains the fix. Until patched, limit the application's internet exposure, apply WAF rules that block SQL injection patterns, and confirm the code path in question uses parameterized queries. Operators should also review web server and database logs for signs of anomalous SQL activity.

Affected
TRtek Technological Products Computer Software Hardware Industry and Trade Limit Products's Storebefore 030631b2
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.