CVE-2025-11909 | Shenzhen Ruiming Technology Streamax Crocus 1.3.40 RepairRecord.do?Action=QueryLast queryLast orderField sql injection (EUVD-2025-34908)
A vulnerability, which was classified as critical, was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation of the argument orderField can lead to sql injection.
This vulnerability appears as CVE-2025-11909. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.