Junglewise Threat Intelligence

CVE-2025-4822: Bayraktar Solar Energies ScadaWatt Otopilot SQL injection

CVE-2025-4822 · Severity: critical · CVSS 9.8 · Published 2025-07-24

Executive brief

Bayraktar Solar Energies ScadaWatt Otopilot, a system used for managing solar energy infrastructure, contains a critical security flaw. This vulnerability allows unauthorized individuals to manipulate the system's database over the internet. An attacker could potentially steal sensitive operational data, modify system configurations, or cause a complete service outage, posing a significant risk to energy production and business continuity.

Technical details

A SQL injection vulnerability (CWE-89) exists in Bayraktar Solar Energies ScadaWatt Otopilot due to improper neutralization of special elements in SQL commands. The flaw is remotely exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can send specially crafted requests to the application to bypass security controls, view sensitive data, modify or delete database records, and potentially gain full administrative control over the backend database. The issue is addressed in versions released on or after May 27, 2025.

Affected products

  • Bayraktar Solar Energies ScadaWatt Otopilot before 27.05.2025

Timeline

  • 2025-07-24: advisory: Initial NVD publication date
  • 2025-05-27: patched: Fixed in versions released on or after this date

References