CVE-2026-78182

A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-24 04:16

Updated : 2026-08-24 18:17


NVD link : CVE-2026-78182

Mitre link : CVE-2026-78182

CVE.ORG link : CVE-2026-78182


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')