FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString (CVE-2026-47720) | HOL Guard CVE