<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Shenzhen Gongji Technology - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/shenzhen-gongji-technology/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 24 Aug 2026 05:41:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/shenzhen-gongji-technology/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in XBROTHER Dynamic Environment Monitoring System</title><link>https://feed.craftedsignal.io/briefs/2026-08-xbrother-sql-injection/</link><pubDate>Mon, 24 Aug 2026 05:41:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-xbrother-sql-injection/</guid><description>An unauthenticated SQL injection vulnerability in the PlanController.getImmediatePlans function of the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System allows remote attackers to execute arbitrary SQL commands.</description><content:encoded><![CDATA[<p>A security vulnerability (CVE-2026-78182) has been identified in the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System, affecting all versions up to and including 300R004C00B300. The vulnerability resides within the <code>PlanController.getImmediatePlans</code> function, which is reachable via the <code>/xbreport/api/v1/plamange/plansImmediate</code> endpoint. An unauthenticated remote attacker can exploit this flaw by providing malicious input to the <code>order</code> or <code>sort</code> parameters, which are improperly neutralized before being processed in a database query. This leads to SQL injection, potentially allowing for unauthorized data access or modification within the underlying database. The vulnerability has been publicly disclosed and exploit code is available, increasing the risk of exploitation. Defenders should restrict network access to affected monitoring systems and prioritize patching.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a remote, unauthenticated attacker to compromise the integrity and confidentiality of the XBROTHER system database. Depending on the database configuration and permissions, this could lead to information disclosure, administrative bypass, or in some scenarios, remote code execution. Given the nature of environmental monitoring systems, these devices are often deployed in critical infrastructure or sensitive server environments, making unauthorized access a significant risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided Sigma rule to web server logs to detect exploitation attempts targeting the identified endpoint.</li>
<li>Patch or update all XBROTHER Dynamic Environment Monitoring System instances to versions beyond 300R004C00B300 immediately.</li>
<li>Restrict network access to the monitoring system management interface to authorized IP ranges only, as the vulnerability is remotely exploitable without authentication.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>sql-injection</category><category>vulnerability</category><category>webserver</category></item></channel></rss>