CVE-2026-9003

7.5

TONNET · E-LAN Hybrid Recording System

The TONNET E-LAN Hybrid Recording System is vulnerable to SQL injection, allowing unauthenticated remote attackers to execute arbitrary SQL commands and read database contents.

Executive summary

The TONNET E-LAN Hybrid Recording System contains a critical SQL injection vulnerability that allows unauthenticated remote attackers to compromise database confidentiality.

Vulnerability

This is an SQL injection vulnerability (CWE-89) that allows unauthenticated, remote attackers to inject arbitrary commands into the backend database. The vulnerability arises from improper neutralization of special elements within the application's input processing.

Business impact

Exploitation of this vulnerability grants attackers the ability to read sensitive data stored within the system's database. With a CVSS score of 7.5, this high-severity flaw poses a severe risk to the integrity and confidentiality of recording system data, potentially leading to unauthorized access to system logs or administrative information.

Remediation

Immediate Action: Update the device firmware to version mdiskTRS08_tonnet_20260203-1636 or later as provided by the vendor.

Proactive Monitoring: Review system and database access logs for unauthorized access attempts or suspicious query patterns originating from untrusted network segments.

Compensating Controls: Restrict network access to the management interface of the E-LAN system using Access Control Lists (ACLs) or by placing the device behind a secure VPN to ensure it is not reachable from the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Security teams must prioritize the firmware update for all affected TONNET E-LAN systems. Due to the nature of embedded device vulnerabilities, ensure that the management interface is isolated from public-facing networks to prevent remote exploitation while the update process is managed.