Metrics
Affected Vendors & Products
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Thu, 10 Jul 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account. | |
Title | Advantech iView SQL Injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-07-10T23:23:38.421Z
Updated: 2025-07-11T13:39:39.168Z
Reserved: 2025-07-02T15:12:58.621Z
Link: CVE-2025-53475

Updated: 2025-07-11T13:39:33.988Z

Status : Awaiting Analysis
Published: 2025-07-11T00:15:27.107
Modified: 2025-07-15T13:14:49.980
Link: CVE-2025-53475

No data.