CVE-2025-47902: SQL Injection in web resource
Published Oct 20, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5.
Affected Software
3 affected components
Microchip Time Provider 4100<2.5
All of the following
Microchip Timeprovider 4100 Firmware<2.5
Microchip TimeProvider 4100
Event History
Oct 20, 2025
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 29, 58216
Event
via NVD·03:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-47902?
CVE-2025-47902 has a critical severity rating due to its potential for SQL Injection vulnerabilities.
2
How do I fix CVE-2025-47902?
To fix CVE-2025-47902, upgrade Microchip Time Provider 4100 to version 2.5 or later.
3
What types of attacks are possible with CVE-2025-47902?
CVE-2025-47902 allows attackers to perform SQL Injection attacks, potentially leading to unauthorized access to sensitive data.
4
Which versions of Time Provider 4100 are affected by CVE-2025-47902?
CVE-2025-47902 affects Microchip Time Provider 4100 versions prior to 2.5.
5
What is the cause of the CVE-2025-47902 vulnerability?
The cause of CVE-2025-47902 is improper neutralization of special elements used in SQL commands, leading to SQL Injection risks.