PT-2025-29186 · Advantech · Advantech Iview

Alex Williams

·

Published

2025-06-13

·

Updated

2025-07-11

·

CVE-2025-53475

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Advantech iView (affected versions not specified)
Description: A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution. The issue resides in the NetworkServlet.getNextTrapPage() function, where certain parameters are not properly sanitized. An authenticated attacker with user-level privileges can exploit this to perform SQL injection and potentially execute code in the context of the 'nt authoritylocal service' account.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-08968
CVE-2025-53475

Affected Products

Advantech Iview