PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Web Vulnerabilities·Updated Jan 22, 2026

Advantech WISE-IoTSuite/SaaS - SQL Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-52694
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
IoTSuite and IoT Edge Productsby Advantech
SaaSComposer prior to version V3.4.15
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Advantech WISE-IoTSuite/SaaS - SQL Injection CVE-2025-52694 Scanner | S4E