Back to overview

CVE-2016-20096

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.

Metadata

CVE ID
CVE-2016-20096
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-21 18:49 UTC
Published
2026-07-21 18:59 UTC
Last updated
2026-07-22 19:06 UTC
Primary CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL C…
Vendor / Product
Kunshi Network Technology Co., Ltd. / Linknat VOS3000
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
Kunshi Network Technology Co., Ltd. Linknat VOS2009 2.1.1.5, 2.1.1.8, 2.1.2.0
Kunshi Network Technology Co., Ltd. Linknat VOS3000 2.1.1.5, 2.1.1.8, 2.1.2.0
Weakness (CWE)
CWESourceDescription
CWE-89 cna Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview