CVE-2025-32859

CWE-89SQL Injection3 documents3 sources
Severity
8.7HIGH
EPSS
0.9%
top 23.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16

Description

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5siemens/telecontrol_server_basic< V3.1.2.2
NVDsiemens/telecontrol< 3.1.2.2

🔴Vulnerability Details

2
GHSA
GHSA-v664-v4vw-9f75: A vulnerability has been identified in TeleControl Server Basic (All versions < V32025-04-16
CVEList
CVE-2025-32859: A vulnerability has been identified in TeleControl Server Basic (All versions < V32025-04-16