CVE-2025-34162 is an unauthenticated SQL injection vulnerability in the Bian Que Feijiu Intelligent Emergency and Quality Control System, specifically within the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface's GetLyfsByParams endpoint. This flaw allows attackers to inject arbitrary SQL statements due to improper input sanitization of the strOpid parameter. With a CVSS score of 9.3 (CRITICAL), the vulnerability has a low attack complexity and can lead to severe impacts including data exfiltration, authentication bypass, and potentially remote code execution. While presumed to affect builds prior to June 2025 and remediated in newer versions, the exact affected range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-23 UTC, indicating active exploitation, though no public exploit code or significant community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Feijiu Medical Technology Co., Ltd. | Bian Que Feijiu Intelligent Emergency And Quality Control System | >= 0, <= pre-June 2025 buildsCNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.