Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
References
| Link | Resource |
|---|---|
| https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ | Mitigation Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
26 Jan 2026, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately. | |
| References | () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Mitigation, Third Party Advisory |
22 Jan 2026, 22:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Third Party Advisory, Mitigation | |
| CPE | cpe:2.3:a:advantech:iotsuite_starter_linux_docker:*:*:*:*:*:*:*:* cpe:2.3:a:advantech:iotsuite_growth_linux_docker:*:*:*:*:*:*:*:* cpe:2.3:a:advantech:iot_edge_windows:*:*:*:*:*:*:*:* cpe:2.3:a:advantech:iotsuite_saas_composer:*:*:*:*:*:*:*:* cpe:2.3:a:advantech:iot_edge_linux_docker:*:*:*:*:*:*:*:* |
|
| First Time |
Advantech iot Edge Windows
Advantech iotsuite Saas Composer Advantech iotsuite Starter Linux Docker Advantech Advantech iot Edge Linux Docker Advantech iotsuite Growth Linux Docker |
12 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 |
12 Jan 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
12 Jan 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-12 03:16
Updated : 2026-01-26 03:15
NVD link : CVE-2025-52694
Mitre link : CVE-2025-52694
CVE.ORG link : CVE-2025-52694
JSON object : View
Products Affected
advantech
- iot_edge_linux_docker
- iotsuite_saas_composer
- iot_edge_windows
- iotsuite_growth_linux_docker
- iotsuite_starter_linux_docker
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
