LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Jul 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. | |
Title | eKuiper API endpoints handling SQL queries with user-controlled table names. | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-24T22:24:23.709Z
Updated: 2025-07-25T13:26:34.392Z
Reserved: 2025-07-21T16:12:20.733Z
Link: CVE-2025-54379

Updated: 2025-07-25T13:26:15.977Z

Status : Awaiting Analysis
Published: 2025-07-24T23:15:26.883
Modified: 2025-07-25T15:29:19.837
Link: CVE-2025-54379

No data.