ZeroHour

CVE-2025-52694

niche

Unauthenticated SQL Injection in Advantech IoT Edge and IoTSuite Platforms

CVSS 3.1
9.8 critical
EPSS
40%p99
Published
()
Modified
AI analysis

CVE-2025-52694 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) affecting multiple Advantech industrial IoT platform products, including IoT Edge (Linux Docker and Windows) and IoTSuite (Growth/Starter Linux Docker and SaaS Composer). An unauthenticated remote attacker can send crafted input to an internet-exposed vulnerable service, where it is processed as SQL commands. Successful exploitation could compromise the confidentiality, integrity, and availability of data handled by the service, potentially enabling data theft, modification, or denial of service. Users and administrators running affected versions of these Advantech products—especially with the service reachable from the Internet—are affected and are advised to update immediately. There is no confirmed in-the-wild exploitation, no public proof-of-concept, and the flaw is not yet in CISA KEV, but an EPSS score of 40.4% (99th percentile) indicates a high probability of exploitation within the next 30 days.

What to do: Immediately update all affected Advantech IoT Edge and IoTSuite components to the latest versions per Advantech's advisory, as specific fixed version numbers are not provided in the available data. Until patched, restrict Internet-facing exposure of these services via firewall rules or a reverse proxy/WAF, and review service logs for anomalous SQL activity or unauthenticated requests. After patching, verify that the service is no longer reachable directly from the Internet.

Affected
Advantech IoT Edge (Linux Docker)
Advantech IoT Edge (Windows)
Advantech IoTSuite Growth (Linux Docker)
Advantech IoTSuite SaaS Composer
Advantech IoTSuite Starter (Linux Docker)
Estimated exposure
nicheunknown (no public install-base or internet-exposure scan data for these products) — Advantech IoT Edge and IoTSuite are specialized industrial IoT platform products typically deployed in limited numbers of industrial and enterprise environments, with no public active-install counts or internet-exposed device statistics…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

Vendors
advantech
Products
iot edge linux docker, iot edge windows, iotsuite growth linux docker, iotsuite saas composer, iotsuite starter linux docker
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.