CVE-2025-59379

HIGH

DwyerOmega Isensix Advanced Remote Monitoring System < 1.5.7 - Blind SQL Injection

Title source: llm
STIX 2.1

Description

DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and admins) and use them to authenticate to the application.

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
dwyeromega/isensix_advanced_remote_monitoring_system_firmware < 1.5.7
Published Jan 06, 2026
Tracked Since Feb 18, 2026