CVE-2025-52694

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
References
Link Resource
https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:advantech:iot_edge_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iot_edge_windows:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_growth_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_saas_composer:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_starter_linux_docker:*:*:*:*:*:*:*:*

History

26 Jan 2026, 03:15

Type Values Removed Values Added
Summary (en) Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet. (en) Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
References () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Third Party Advisory, Mitigation () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Mitigation, Third Party Advisory

22 Jan 2026, 22:09

Type Values Removed Values Added
References () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ - Third Party Advisory, Mitigation
CPE cpe:2.3:a:advantech:iotsuite_starter_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_growth_linux_docker:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iot_edge_windows:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iotsuite_saas_composer:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:iot_edge_linux_docker:*:*:*:*:*:*:*:*
First Time Advantech iot Edge Windows
Advantech iotsuite Saas Composer
Advantech iotsuite Starter Linux Docker
Advantech
Advantech iot Edge Linux Docker
Advantech iotsuite Growth Linux Docker

12 Jan 2026, 15:16

Type Values Removed Values Added
CWE CWE-89

12 Jan 2026, 10:16

Type Values Removed Values Added
References
  • {'url': 'https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-127/', 'source': '5f57b9bf-260d-4433-bf07-b6a79e9bb7d4'}
  • () https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ -

12 Jan 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 03:16

Updated : 2026-01-26 03:15


NVD link : CVE-2025-52694

Mitre link : CVE-2025-52694

CVE.ORG link : CVE-2025-52694


JSON object : View

Products Affected

advantech

  • iot_edge_linux_docker
  • iotsuite_saas_composer
  • iot_edge_windows
  • iotsuite_growth_linux_docker
  • iotsuite_starter_linux_docker
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')