← Retour aux CVEs
CVE-2025-52694
CRITICAL10.0
Description
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
Details CVE
Score CVSS v3.110.0
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie1/12/2026
Derniere modification1/26/2026
Sourcenvd
Observations honeypot0
Produits affectes
advantech:iot_edge_linux_dockeradvantech:iot_edge_windowsadvantech:iotsuite_growth_linux_dockeradvantech:iotsuite_saas_composeradvantech:iotsuite_starter_linux_docker
Faiblesses (CWE)
CWE-89
References
https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/(5f57b9bf-260d-4433-bf07-b6a79e9bb7d4)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.