PT-2026-62046 · Linknat · Vos2009+1
CVE-2016-20096
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linknat VOS3000 versions prior to 2.1.2.1
Linknat VOS2009 versions prior to 2.1.2.1
Description
An unauthenticated SQL injection allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the
name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve the results from a subsequent session request, enabling the extraction of plaintext credentials and other database content with DBA-level privileges.Recommendations
Update Linknat VOS3000 to a version newer than 2.1.2.0.
Update Linknat VOS2009 to a version newer than 2.1.2.0.
Avoid using the
name parameter in the login endpoint until the software is updated.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vos2009
Vos3000