Critical Vulnerability in Advantech Products
12 January 2026
CSA has issued 1 CVE ID to a vulnerability in Advantech Products. Users and administrators of the affected product versions are advised to update to the latest versions immediately.
Background
Advantech has released security updates addressing a critical vulnerability (CVE-2025-52694) in their products. The vulnerability has a Common Vulnerability Scoring System (CVSS 3.1) score of 10 out of 10.
Impact
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet.
Affected Products
The vulnerability affects the following Advantech products:
IoTSuite SaaSComposer prior to version 3.4.15
IoTSuite Growth Linux docker prior to version V2.0.2
IoTSuite Starter Linux docker prior to version V2.0.2
IoT Edge Linux docker prior to version V2.0.2
IoT Edge Windows prior to version V2.0.2
Mitigation
Users and administrators of affected product versions are advised to update to the latest versions immediately.
For IoTSuite SaaSComposer, IoTSuite Growth Linux docker, and IoT Edge Windows please contact Advantech here for the official release of the fixed version.
For IoTSuite Starter Linux docker, please download the update here.
For IoT Edge Linux docker, please download the update here.
Credits
CSA would like to express our appreciation to Mr Loi Nguyen Thang from HCMUTE Information Security Club for discovering the vulnerability and thank Advantech for their collaboration on the coordinated disclosure of the vulnerability.
References
https://www.advantech.com/en/security-advisory
