{"apiVersion":"1.0","identifier":"CVE-2026-78182","description":"A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.","publishedAt":"2026-08-24T04:16:59","lastModifiedAt":"2026-08-24T18:17:28","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78182","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","epssProbability":0.00313,"riskScore":0.75,"affectedProduct":"XBROTHER Dynamic Environment Monitoring System","affectedVersions":"cannotmatch","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-78182","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-78182","en":"https://www.redsauce.net/en/cves/CVE-2026-78182","fr":"https://www.redsauce.net/fr/cves/CVE-2026-78182","pt":"https://www.redsauce.net/pt/cves/CVE-2026-78182","de":"https://www.redsauce.net/de/cves/CVE-2026-78182","sk":"https://www.redsauce.net/sk/cves/CVE-2026-78182","el":"https://www.redsauce.net/el/cves/CVE-2026-78182"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-78182"}}