CVE-2022-50594 Details
Description
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
A vulnerability exists in Advantech iView versions prior to 5.7.04 build 6425 within the SNMP management tool. This vulnerability allows remote attackers to bypass authentication checks and exploit a SQL injection flaw in the 'data' parameter of the 'NetworkServlet' endpoint. Successful exploitation could lead to the exfiltration of user data, including clear text passwords.
Users can upgrade to Advantech iView version 5.7.04 build 6425 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| advantech iview | < 5.7.04.6425 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 24, 2025 | Initial Analysis | [email protected] |
| Nov 6, 2025 | New CVE Received | [email protected] |