6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XForm/BM/BusComManagement/TireMng.aspx. Executing a manipulation of the argument key can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Basic Information
ID
CVE-2026-1449
Source
VulDB
Published
Jan 26, 2026 at 23:32
Affected Product
Vendor
Hisense TransTech
Product
Smart Bus Management System
Version
20260113
Affected Versions
Hisense TransTech Smart Bus Management System 20260113