CVE-2025-59379

DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and admins) and use them to authenticate to the application.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dwyeromega:isensix_advanced_remote_monitoring_system_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dwyeromega:isensix_advanced_remote_monitoring_system:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-06 16:15

Updated : 2026-01-29 01:41


NVD link : CVE-2025-59379

Mitre link : CVE-2025-59379

CVE.ORG link : CVE-2025-59379


JSON object : View

Products Affected

dwyeromega

  • isensix_advanced_remote_monitoring_system_firmware
  • isensix_advanced_remote_monitoring_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')