PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-34162 Feijiu Medical Technology Co., Ltd. CVE debrief

A critical SQL injection vulnerability exists in the Bian Que Feijiu Intelligent Emergency and Quality Control System, specifically in the GetLyfsByParams endpoint. This unauthenticated vulnerability allows attackers to inject arbitrary SQL statements, potentially leading to data exfiltration, authentication bypass, and remote code execution. The vulnerability is presumed to affect builds released prior to June 2025 and is remediated in newer versions. Exploitation evidence was first observed by the Shadowserver Foundation on July 23, 2025.

Vendor
Feijiu Medical Technology Co., Ltd.
Product
Bian Que Feijiu Intelligent Emergency and Quality Control System
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-27
Original CVE updated
2026-09-26
Advisory published
2025-08-27
Advisory updated
2026-09-26

Who should care

Defenders and security teams responsible for the Bian Que Feijiu Intelligent Emergency and Quality Control System should immediately assess their systems for exposure and apply remediation if necessary. This vulnerability requires high priority attention due to its critical severity and potential for data exfiltration and remote code execution.

Why it matters

CVE-2025-34162 is a critical SQL injection vulnerability in the Bian Que Feijiu Intelligent Emergency and Quality Control System that requires immediate attention from defenders and security teams. The vulnerability allows attackers to inject arbitrary SQL statements, potentially leading to data exfiltration, authentication bypass, and remote code execution. Affected systems should be assessed and remediated promptly to prevent exploitation.

  • Potential data exfiltration requires immediate attention to protect sensitive information
  • Authentication bypass could lead to unauthorized access and control
  • Possible remote code execution necessitates prompt remediation to prevent lateral movement
  • Verification of system builds and remediation priority is crucial to prevent exploitation

Technical summary

The Bian Que Feijiu Intelligent Emergency and Quality Control System is vulnerable to a critical SQL injection vulnerability in the GetLyfsByParams endpoint. The vulnerability is caused by improper sanitization of user-supplied input in the strOpid parameter, allowing attackers to inject arbitrary SQL statements. This can lead to data exfiltration, authentication bypass, and potentially remote code execution, depending on backend configuration.

Defensive priority

High priority for immediate assessment and remediation

Recommended defensive actions

  • Immediately assess the Bian Que Feijiu Intelligent Emergency and Quality Control System for exposure
  • Verify if the system build is prior to June 2025 and apply remediation if necessary
  • Implement compensating controls to monitor and restrict access to the affected endpoint
  • Review and update incident response plans to address potential data exfiltration and authentication bypass
  • Perform vulnerability scanning to identify exposed systems
  • Establish a remediation timeline for affected systems
  • Monitor for suspicious activity related to the vulnerability

Evidence notes

The vulnerability was discovered in the Bian Que Feijiu Intelligent Emergency and Quality Control System, specifically in the GetLyfsByParams endpoint. The backend fails to properly sanitize user-supplied input in the strOpid parameter, allowing attackers to inject arbitrary SQL statements. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-23 UTC.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-34162 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-34162

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-34162 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-34162

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.