Garmin was notified of a vulnerability under a responsible disclosure policy and has released an update. To remediate the issue, users should update the app to version 5.18 or higher as soon as possible. The Positive Technologies expert also reminded users to download smartphone apps only from official stores to reduce the risk of personal data leaks and other adverse consequences.
This is not the first such issue discovered by Positive Technologies experts. In May 2025, Alexey Solovyov, Head of the Web Application Security Expertise, and Yan Chizhevsky, a specialist in the same department, helped fix multiple flaws in the Russian NetCat CMS, including an SQL injection vulnerability (BDU:2024-06394). Earlier, in the summer of 2024, Alexey Solovyov found similar vulnerabilities in the Pandora FMS infrastructure monitoring software (CVE-2023-44090 and CVE-2023-44091), and in the Cacti monitoring system (CVE-2023-49085; BDU:2024-01113). The vulnerabilities in these three products could have been used as part of an attack chain leading to arbitrary code execution on a server.
SQL code injection vulnerabilities can be detected at the product development stage with the help of a statistical code analysis tool such as PT Application Inspector.
For up-to-date security information, visit the dbugs portal, which aggregates vulnerability data and vendor recommendations for software and hardware from vendors around the world.