← Back to CVE List
CVE-2025-52694NVD
Vulnerability Summary
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
CVSS v3.1 Base Metrics — Score 10.0 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Advantech Iot Edge Linux Docker < 2.0.2
- Advantech Iot Edge Windows < 2.0.2
- Advantech Iotsuite Growth Linux Docker < 2.0.2
- Advantech Iotsuite Saas Composer < 3.4.15
- Advantech Iotsuite Starter Linux Docker < 2.0.2
- Advantech Iot Edge Linux Docker 2.0.2
- Advantech Iot Edge Windows 2.0.2
- Advantech Iotsuite Growth Linux Docker 2.0.2
- Advantech Iotsuite Saas Composer 3.4.15
- Advantech Iotsuite Starter Linux Docker 2.0.2