← Back to browse · API

CVE-2025-52694

Severity
CRITICAL
CVSS
10.0
EPSS
0.37867
Risk score
53.25
CISA KEV
No
PoC
No
Published
2026-01-12
Modified
2026-01-26
First seen
2026-08-07
Aliases
EUVD-2026-1958, GHSA-77R3-GHGF-32GR
Products
Advantech:IoTSuite and IoT Edge Products ECOWatch SaaS-Composer prior to version 3.4.15, Advantech:IoTSuite and IoT Edge Products IoT Edge Linux docker prior to version V2.0.2, Advantech:IoTSuite and IoT Edge Products IoT Edge Windows prior to version V2.0.2, Advantech:IoTSuite and IoT Edge Products IoTSuite Growth Linux docker prior to version V2.0.2, Advantech:IoTSuite and IoT Edge Products IoTSuite Starter Linux docker prior to version V2.0.2, Advantech:IoTSuite and IoT Edge Products SaaSComposer prior to version V3.4.15, Advantech:IoTSuite and IoT Edge Products WebAccess SaaS-Composer prior to version 3.4.15.1, Advantech:IoTSuite and IoT Edge Products WebAccess/SCADA prior to version V9.2.2
Sources
euvd EUVD-2026-1958

Description

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

References