Skip to content

Conversation

@Winz18
Copy link

@Winz18 Winz18 commented Jan 12, 2026

Updates

  • Affected products
  • CWEs
  • Description
  • References
  • Source code location
  • Summary

Comments
I am reporter of this CVE, Loi Nguyen Thang, see the credits section in this advisory of CSA for details:
https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/
My PoC for vulnerability verifying:
https://github.com/Winz18/CVE-2025-52694-POC

Copilot AI review requested due to automatic review settings January 12, 2026 12:00
@github-actions github-actions bot changed the base branch from main to Winz18/advisory-improvement-6637 January 12, 2026 12:01
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates the security advisory GHSA-77r3-ghgf-32gr for CVE-2025-52694, a critical SQL injection vulnerability in Advantech IoTSuite and IoT Edge products. The reporter is adding comprehensive technical details, affected product information, and remediation guidance based on their original research.

Changes:

  • Added detailed vulnerability summary and technical description with exploitation mechanisms
  • Updated CWE classification to CWE-89 (SQL Injection)
  • Modified references to include POC repository and official CSA advisory
  • Added affected products section with ecosystem and version range information

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@yhidad31
Copy link

Hi @Winz18, thanks for the contribution. Unfortunately we can't accept this change because the affected products, Advantech IoTSuite & IoT Edge appear to be enterprise software. If you can point to a package in a supported open-source registry, we can reevaluate. Thank you for helping improve the database.

@yhidad31 yhidad31 closed this Jan 14, 2026
@github-actions github-actions bot deleted the Winz18-GHSA-77r3-ghgf-32gr branch January 14, 2026 22:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants