Database/Control plane, storage & DevOps

Sunbird Power IQ 9.2.0 API: Error-based SQL injection through an outdated API endpoint with missing input validation
CVE-2025-55703Control plane, storage & DevOpscurated
Impact
Error-based SQL injection through an outdated API endpoint with missing input validation. Low score, but Power IQ is the power-monitoring layer that holds PDU credentials and outlet-level topology for the estate, so any read primitive into its database is worth closing.
Who can reach it
Access to the Power IQ API.
What to do
Apply the Sunbird fix. Additionally, disable legacy API endpoints you do not use - the root cause here is an old endpoint left enabled.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.