TROYANOSYVIRUS
Volver a CVEs

CVE-2025-52694

CRITICAL
10.0

Descripcion

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

Detalles CVE

Puntuacion CVSS v3.110.0
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado1/12/2026
Ultima modificacion1/26/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

advantech:iot_edge_linux_dockeradvantech:iot_edge_windowsadvantech:iotsuite_growth_linux_dockeradvantech:iotsuite_saas_composeradvantech:iotsuite_starter_linux_docker

Debilidades (CWE)

CWE-89

Referencias

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.