PT-2025-29183 · Advantech · Advantech Iview

Alex Williams

·

Published

2025-06-13

·

Updated

2025-07-11

·

CVE-2025-52459

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Advantech iView (affected versions not specified)
Description: A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.backupDatabase() function. An authenticated attacker with user-level privileges can inject arbitrary arguments due to improper sanitization of certain parameters used in commands. This can lead to information disclosure, including sensitive database credentials.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the NetworkServlet.backupDatabase() function to minimize the risk of exploitation. Ensure proper sanitization of all input parameters used in command execution within the NetworkServlet class.

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08964
CVE-2025-52459

Affected Products

Advantech Iview