CVE-2025-49853: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premises
Published Jun 24, 2025
·Updated
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.
Affected Software
2 affected components
: ControlID iDSecure On-premises<=4.7.48.0
Assaabloy Control Id Idsecure<4.7.50.0
Remediation
Information
ControlID has released the following versions for users to update:
* iDSecure On-premises: Version 4.7.50.0 https://www.controlid.com.br/en/access-control/idsecure/
For more information, contact ControlID https://www.controlid.com.br/en/contact/ .
Event History
Jun 24, 2025
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via ICS·07:23 PM
SeverityWeaknessAffected Software
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49853?
CVE-2025-49853 is considered critical due to its potential to allow SQL injection attacks that can lead to data leaks.
2
How do I fix CVE-2025-49853?
To remediate CVE-2025-49853, upgrade the ControlID iDSecure On-premises software to version 4.7.49.0 or later.
3
What vulnerabilities does CVE-2025-49853 exploit?
CVE-2025-49853 exploits SQL injection vulnerabilities in ControlID iDSecure On-premises versions up to 4.7.48.0.
4
What types of attacks can CVE-2025-49853 facilitate?
CVE-2025-49853 can facilitate arbitrary information leakage and unauthorized SQL command execution.
5
Which versions of ControlID iDSecure are affected by CVE-2025-49853?
ControlID iDSecure On-premises versions 4.7.48.0 and prior are affected by CVE-2025-49853.