CVE Database
/

CVE-2025-52694

Back to search

CVE-2025-52694

Published: Jan 12, 2026

Modified: Jan 26, 2026

PUBLISHED

CVSS v3.1

10.0

CRITICAL

Description

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

VendorProductVersions

Advantech

IoTSuite and IoT Edge Products

affected
SaaSComposer prior to version V3.4.15
affected
IoTSuite Growth Linux docker prior to version V2.0.2
affected
IoTSuite Starter Linux docker prior to version V2.0.2
affected
IoT Edge Linux docker prior to version V2.0.2
affected
IoT Edge Windows prior to version V2.0.2

+3 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now