{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/linknat/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2016-20096"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VOS3000 \u003c= 2.1.2.0","VOS2009 \u003c= 2.1.2.0"],"_cs_severities":["critical"],"_cs_tags":["sql-injection","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Linknat"],"content_html":"\u003cp\u003eCVE-2016-20096 details a critical unauthenticated SQL injection vulnerability affecting Linknat VOS3000 and VOS2009 software, specifically in versions up to and including 2.1.2.0. This flaw allows remote attackers to compromise the system by injecting malicious SQL commands into the 'name' parameter during a POST request to the application's login endpoint. The vulnerability permits the execution of arbitrary SQL commands, enabling attackers to extract sensitive data, including plaintext credentials and other database content, with privileges equivalent to a Database Administrator (DBA). The exploitation does not require any prior authentication, making it a severe initial access vector. This vulnerability poses a significant risk as it can lead to full compromise of the affected VoIP billing and customer management systems, impacting data confidentiality and integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated remote attacker crafts a specially designed POST request targeting the \u003ccode\u003e/login\u003c/code\u003e endpoint of a vulnerable Linknat VOS3000 or VOS2009 instance.\u003c/li\u003e\n\u003cli\u003eThe attacker embeds malicious SQL injection payloads within the \u003ccode\u003ename\u003c/code\u003e parameter of the POST request, such as \u003ccode\u003eadmin' OR 1=1--\u003c/code\u003e or \u003ccode\u003eadmin' UNION SELECT username,password FROM users--\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe vulnerable application processes this request, failing to properly sanitize the input, which causes the injected SQL commands to be executed on the backend database.\u003c/li\u003e\n\u003cli\u003eThe injected SQL commands are designed to extract sensitive information, such as plaintext user credentials, session tokens, or other valuable database content, leveraging DBA-level privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker then initiates a subsequent session request to the application to retrieve the results of the executed SQL query.\u003c/li\u003e\n\u003cli\u003eThe application's response to the session request inadvertently includes the data extracted by the malicious SQL command.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully obtains plaintext credentials and other sensitive database information, thereby achieving unauthorized, high-privilege access to the system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2016-20096 grants unauthenticated remote attackers the ability to execute arbitrary SQL commands with DBA-level privileges. This directly leads to the complete extraction of sensitive database content, including plaintext user credentials. Organizations utilizing affected Linknat VOS3000 or VOS2009 versions face severe risks to data confidentiality and integrity. If exploited, attackers can gain unauthorized access to the entire system, potentially disrupt VoIP services, compromise customer data, and establish persistent access, leading to further attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch Linknat VOS3000 and VOS2009 to a version higher than 2.1.2.0 to remediate CVE-2016-20096.\u003c/li\u003e\n\u003cli\u003eDeploy the \u003ccode\u003eDetects CVE-2016-20096 Exploitation - SQL Injection via Login Endpoint\u003c/code\u003e Sigma rule to your SIEM to detect attempts to exploit this vulnerability.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for POST requests to the \u003ccode\u003e/login\u003c/code\u003e endpoint containing suspicious characters or SQL keywords in the \u003ccode\u003ename\u003c/code\u003e parameter, as identified by the Sigma rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T19:21:49Z","date_published":"2026-07-21T19:21:49Z","id":"https://feed.craftedsignal.io/briefs/2026-07-linknat-sql-injection/","summary":"An unauthenticated SQL injection vulnerability (CVE-2016-20096) exists in Linknat VOS3000 and VOS2009 through version 2.1.2.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'name' parameter in a POST request to the login endpoint, which leads to the extraction of plaintext credentials and other database content with DBA-level privileges.","title":"Unauthenticated SQL Injection Vulnerability in Linknat VOS3000 and VOS2009","url":"https://feed.craftedsignal.io/briefs/2026-07-linknat-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Linknat","version":"https://jsonfeed.org/version/1.1"}