CVE-2025-53475 Details
Description
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.
A vulnerability in Advantech iView prior to version 5.7.05 build 7057 allows authenticated attackers with user-level privileges to exploit SQL injection and execute remote code. The issue arises in the NetworkServlet.getNextTrapPage() function, where certain parameters are inadequately sanitized. This exploitation could lead to the execution of code under the 'nt authority\local service' account.
Users are advised to update to Advantech iView version 5.7.05 build 7057.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.advantech.com/en/support/details/firmware-?id=1-HIPU-183 | [email protected] | Product |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CISA-ADP |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| advantech iview | < 5.7.05.7057 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2025 | Initial Analysis | [email protected] |
| Jul 11, 2025 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | New CVE Received | [email protected] |