Executive brief
Karel KarelIPS is an industrial control and network management system used to monitor and protect critical infrastructure. A SQL injection vulnerability allows attackers to execute arbitrary database commands by injecting malicious SQL through unsanitized input, potentially exposing sensitive configuration data, credentials, or enabling unauthorized system modifications. The vendor has confirmed the product is no longer supported, meaning no patch is available.
Technical details
An improper neutralization of special characters in SQL queries (CWE-89) creates a blind SQL injection condition in KarelIPS. The vulnerability permits attackers to infer database structure and extract data through time-based or boolean-based blind injection techniques without direct output. Exploitation typically requires network access to the application interface; the attack vector and authentication requirements are not fully specified but the high CVSS score (9.8) suggests minimal preconditions.
Affected products
- Karel KarelIPS through 22092026
Timeline
- 2026-09-22: disclosed