Junglewise Threat Intelligence

CVE-2025-10437: Eksagate Webpack Management System SQL injection

CVE-2025-10437 · Severity: critical · CVSS 9.8 · Published 2025-11-19

Executive brief

A critical security vulnerability has been identified in the Eksagate Webpack Management System, a platform used for industrial or enterprise management. This flaw allows an attacker to bypass security controls and interact directly with the system's database without needing a password. Successful exploitation could lead to the theft of sensitive company data, unauthorized modification of records, or a complete shutdown of the management service.

Technical details

The Eksagate Webpack Management System contains an SQL injection vulnerability (CWE-89) due to improper neutralization of special elements used in SQL commands. The vulnerability is exploitable over the network without authentication (PR:N) and requires no user interaction (UI:N). An attacker can send specially crafted requests to the application to execute arbitrary SQL queries against the backend database. This can result in full unauthorized access to sensitive data, modification of database records, and potential denial of service. The issue affects versions through 20251119.

Affected products

  • Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System through 20251119

Timeline

  • 2025-11-19: disclosed
  • 2025-11-19: advisory

References