Database/Control plane, storage & DevOps

Sunbird Power IQ 9.2.0 API: Error-based SQL injection through an outdated API endpoint with missing input validation
CVSS 2.5CVE-2025-55703Control plane, storage & DevOpscurated
Impact
Error-based SQL injection through an outdated API endpoint with missing input validation. Low score, but Power IQ is the power-monitoring layer that holds PDU credentials and outlet-level topology for the estate, so any read primitive into its database is worth closing.
Who can reach it
Access to the Power IQ API.
What to do
Apply the Sunbird fix. Additionally, disable legacy API endpoints you do not use - the root cause here is an old endpoint left enabled.
References
Related entries
- Trivy: Terraform filesystem functions read paths above the scan root during misconfig scansCVE-2026-104994 · Trivy (Terraform misconfiguration scanner, filesystem functions)Low
- Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode): SR670 V2 servers built between roughly June 2021 and JulyCVE-2024-23591 · Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode)Low
- Linuxfabrik monitoring plugins: symlink attack on predictable /tmp SQLite caches lets a local user write as rootCVE-2026-53759 · linuxfabrik-lib db_sqlite.py (Monitoring Plugins cache databases in /tmp)Low
- Grafana Alerting: Editor can exfiltrate contact point credentials by retargeting the test endpointCVE-2025-12141 · Grafana Alerting (contact point test, redacted secure settings)Low
- QCT (Quanta Cloud Technology) server security centre: QCT firmware is unmeasurable from public data despiteNCVD-2026-012-qct-quanta-cloud-technology-serv · QCT (Quanta Cloud Technology) server security centreUnscored
- Supermicro's public security advisory portal itself: An operator cannot programmatically track Supermicro firmwareNCVD-2026-013-supermicro-s-public-security-adv · Supermicro's public security advisory portal itselfUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.