CVE-2025-52694

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
References
Link Resource
https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:advantech:iot_edge_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iot_edge_windows:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_growth_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_saas_composer:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_starter_linux_docker:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:36

Type Values Removed Values Added
Summary
  • (es) El éxito en la explotación de la vulnerabilidad de inyección SQL podría permitir a un atacante remoto no autenticado ejecutar comandos SQL arbitrarios en el servicio vulnerable cuando este está expuesto a Internet, lo que podría afectar la confidencialidad, integridad y disponibilidad de los datos. Se recomienda a los usuarios y administradores de las versiones de productos afectadas que actualicen a las últimas versiones de inmediato.

26 Jan 2026, 03:15

Type Values Removed Values Added
Summary (en) Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet. (en) Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
References () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Third Party Advisory, Mitigation () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Mitigation, Third Party Advisory

22 Jan 2026, 22:09

Type Values Removed Values Added
First Time Advantech iot Edge Windows
Advantech iotsuite Saas Composer
Advantech iotsuite Starter Linux Docker
Advantech
Advantech iot Edge Linux Docker
Advantech iotsuite Growth Linux Docker
References () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Third Party Advisory, Mitigation
CPE cpe:2.3:a:advantech:iotsuite_starter_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_growth_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iot_edge_windows:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_saas_composer:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iot_edge_linux_docker:*:*:*:*:*:*:*:*

12 Jan 2026, 15:16

Type Values Removed Values Added
CWE CWE-89

12 Jan 2026, 10:16

Type Values Removed Values Added
References
  • {'url': 'https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-127/', 'source': '5f57b9bf-260d-4433-bf07-b6a79e9bb7d4'}
  • () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ -

12 Jan 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 03:16

Updated : 2026-06-17 09:36


NVD link : CVE-2025-52694

Mitre link : CVE-2025-52694

CVE.ORG link : CVE-2025-52694


JSON object : View

Products Affected

advantech

  • iotsuite_starter_linux_docker
  • iotsuite_saas_composer
  • iotsuite_growth_linux_docker
  • iot_edge_linux_docker
  • iot_edge_windows
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')