LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-48650

CVE-2025-48650 - Vulnerability Analysis

HighCVSS: 8.4

Last Updated: March 3, 2026

Unknown - SQL Injection

Published: March 2, 2026Updated: March 3, 2026

Overview

Unknown product contains a sql injection caused by unsanitized input in multiple locations, letting attackers disclose information and escalate privileges locally, exploit requires no user interaction.

Severity & Score

Severity: High
CVSS Score: 8.4
EPSS Score: 0.7%(Probability of exploitation in next 30 days)

Impact

Attackers can disclose sensitive information and escalate privileges locally without additional execution rights.

Mitigation

Update to the latest version.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 3, 2026

🟠 CVE-2025-48650 - High (8.4) In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-48650/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-48650
Severity
High
CVSS Score
8.4
Type
sql_injection
Status
confirmed
EPSS
0.7%
Social Posts
1

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.7%Probability of exploitation in the next 30 days