8.9
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1.
Basic Information
ID
CVE-2025-54379
Source
GitHub_M
Published
Jul 24, 2025 at 22:24
Modified
Jul 25, 2025 at 13:26
Affected Product
Vendor
lf-edge
Product
ekuiper
Version
< 2.2.1
Affected Versions
lf-edge ekuiper < 2.2.1