Several high-severity vulnerabilities were disclosed across IoT/OT infrastructure products, creating pathways to unauthenticated remote code execution or full device compromise. Ruckus vRIoT IoT Controller was reported to contain two CVSS 10.0 issues—CVE-2025-69425 and CVE-2025-69426—driven by hardcoded secrets/credentials that enable attackers to bypass authentication and obtain root-level command execution, including via a service listening on TCP port 2004. Separately, Singapore’s CSA issued a high-priority alert for Advantech software affected by a CVSS 10.0 SQL injection (CVE-2025-52694) that allows an unauthenticated remote attacker to execute arbitrary SQL commands against exposed services, impacting multiple IoTSuite and IoT Edge components and requiring upgrades (some obtained via vendor support channels).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Public disclosure described how CVE-2025-69425 abuses a hardcoded TOTP secret and static token to access a root-privileged command execution service on TCP port 2004, while CVE-2025-69426 uses hardcoded SSH credentials and Docker socket access to escape a container and modify the host OS. The disclosure warned administrators to upgrade immediately.
Ruckus fixed two CVSS 10.0 vulnerabilities in the vRIoT IoT Controller in firmware version 3.0.0.0 (GA). The flaws, CVE-2025-69425 and CVE-2025-69426, affect all firmware versions prior to 3.0.0.0 and can lead to root-level remote code execution.
Fixed releases and remediation guidance were made available for multiple affected Advantech IoTSuite and IoT Edge components, with some updates downloadable directly and others requiring customers to contact Advantech support. Administrators were urged to upgrade immediately to prevent data theft, configuration tampering, and wider compromise.
A critical SQL injection vulnerability in Advantech IoT products, tracked as CVE-2025-52694 and discovered by Loi Nguyen Thang of the HCMUTE Information Security Club, was disclosed through coordinated disclosure involving Advantech and Singapore's Cyber Security Agency. The flaw can let an unauthenticated remote attacker execute arbitrary SQL commands against exposed services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.