PT-2025-49175 · Advantech · Iview
Published
2025-12-04
·
Updated
2025-12-05
·
CVE-2025-13373
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Advantech iView versions 5.7.05.7057 and prior
Description
Advantech iView does not properly sanitize SNMP v1 trap (Port 162) requests, potentially allowing an attacker to inject SQL commands. The vulnerability exists due to insufficient input validation when processing SNMP v1 traps received on port 162. An attacker could exploit this to execute arbitrary SQL commands.
Recommendations
Update to a newer version of Advantech iView.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iview