CVE-2025-52694 - CVE House
Back to Database
Status published Critical CVE-2025-52694

Execution of arbitrary SQL commands

Vulnerability Description

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52694

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Loi Nguyen Thang

Affected Vendor

Affected Software

IoTSuite and IoT Edge Products
Vulnerable Versions:
SaaSComposer prior to version V3.4.15, IoTSuite Growth Linux docker prior to version V2.0.2, IoTSuite Starter Linux docker prior to version V2.0.2, IoT Edge Linux docker prior to version V2.0.2, IoT Edge Windows prior to version V2.0.2, WebAccess/SCADA prior to version V9.2.2, WebAccess SaaS-Composer prior to version 3.4.15.1, ECOWatch SaaS-Composer prior to version 3.4.15

Timeline

Official Publish: January 12th, 2026
Last Modified: January 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.