CVE-2016-20096
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.
Published:Jul 21, 2026
Last Modified:Jul 23, 2026
EPS:Jul 21, 2026
EPSS Score:0.00382
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Kunshi Network Technology
Product
Linknat Vos3000
Kunshi Network Technology
Linknat Vos3000
Vendor
Kunshi Network Technology Co., Ltd.
Product
Linknat Vos2009
Kunshi Network Technology Co., Ltd.
Linknat Vos2009
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
