logo

CVE-2025-52694 (CVSS 10): Critical Advantech SQL Injection Exposes IoT Devices

ID: f72bf24d-c587-55ec-a193-211c986f796e

STIX ID: report--f72bf24d-c587-55ec-a193-211c986f796e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

The Cyber Security Agency of Singapore (CSA) and Advantech disclosed CVE-2025-52694, an unauthenticated SQL injection affecting multiple Advantech IoT management and edge products (CVSS 10.0). Successful exploitation allows remote attackers to execute arbitrary SQL commands, potentially leading to data theft, configuration modification, or full control of affected IoT infrastructure; administrators are advised to apply the provided updates or request fixed versions from Advantech immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.