Home

Description

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

PUBLISHED Reserved 2025-11-05 | Published 2025-11-06 | Updated 2025-11-06 | Assigner VulnCheck




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unaffected

Any version before 5.7.04 build 6425
affected

Timeline

2022-03-01:Exodus Intelligence publicly discloses technical details of vulnerability.
2022-01-27:Advantech releases patched version - 5.7.04 build 6425.

Credits

Exodus Intelligence finder

References

www.advantech.tw/support/details/firmware?id=1-HIPU-183 release-notes patch

blog.exodusintel.com/...remote-code-execution-vulnerability/ technical-description

www.vulncheck.com/...ech-iview-searchterm-parameter-sqli-rce third-party-advisory

cve.org (CVE-2022-50593)

nvd.nist.gov (CVE-2022-50593)

Download JSON