CVE-2025-52694 Details
Description
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
A SQL injection vulnerability has been identified in several Advantech products, including IoTSuite SaaSComposer, IoTSuite Growth Linux docker, IoTSuite Starter Linux docker, IoT Edge Linux docker, and IoT Edge Windows. This vulnerability allows an unauthenticated remote attacker to execute arbitrary SQL commands on the affected service when it is exposed to the Internet. The vulnerability exists in Advantech IoTSuite SaaSComposer versions prior to 3.4.15, IoTSuite Growth Linux docker versions prior to V2.0.2, IoTSuite Starter Linux docker versions prior to V2.0.2, IoT Edge Linux docker versions prior to V2.0.2, and IoT Edge Windows versions prior to V2.0.2.
Users and administrators are advised to update to the latest versions of the affected products. For IoTSuite SaaSComposer, IoTSuite Growth Linux docker, and IoT Edge Windows, contact Advantech for the official release of the fixed version. For IoTSuite Starter Linux docker and IoT Edge Linux docker, download the update from the Advantech KB Insight portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/ | CSA | MitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| advantech iot edge linux docker | < 2.0.2 |
CPE
Remediation
| |
| advantech iot edge windows | < 2.0.2 |
CPE
Remediation
| |
| advantech iotsuite growth linux docker | < 2.0.2 |
CPE
Remediation
| |
| advantech iotsuite saas composer | < 3.4.15 |
CPE
Remediation
| |
| advantech iotsuite starter linux docker | < 2.0.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | CSA |
| Jan 26, 2026 | CVE Modified | CSA |
| Jan 22, 2026 | Initial Analysis | [email protected] |
| Jan 12, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | CVE Modified | CSA |
| Jan 12, 2026 | New CVE Received | CSA |