CVE-2026-12718: SQLi in Karel Electronics' KarelIPS
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection.
This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Affected Software
Event History
Frequently Asked Questions
Which KarelIPS deployments are affected?
The issue affects KarelIPS versions through 22092026. The provided information does not identify a fixed release.
Can this be exploited remotely without credentials or user interaction?
Yes. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the likely impact of successful exploitation?
The vulnerability is a blind SQL injection and is rated with high confidentiality, integrity, and availability impact. Successful exploitation could affect data confidentiality, modification, and service availability.
Is vendor support or a patch expected?
The vendor stated that the product is not supported. No supported remediation or fixed version is identified in the provided information.