CVE-2025-52694
10.0
CRITICAL · CVSS 3.1 · EPSS 40.4% (pctl 99)
Patch early
EPSS 40.4% — above the 10% action threshold.
Description
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 40.38% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2026-01-12 |
| Last modified | 2026-06-17 |
Affected (5)
| Vendor | Product |
|---|---|
| advantech | iot edge linux docker |
| advantech | iot edge windows |
| advantech | iotsuite growth linux docker |
| advantech | iotsuite saas composer |
| advantech | iotsuite starter linux docker |
→ the Explorer · watch your stack · NVD