We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command without proper sanitization, allowing arbitrary arguments to be injected. This can result in information disclosure, including sensitive database credentials.
Reserved 2025-07-02 | Published 2025-07-10 | Updated 2025-07-11 | Assigner icscertAlex Williams of Converge Technology Solutions reported these vulnerabilities to CISA.
www.cisa.gov/news-events/ics-advisories/icsa-25-191-08
www.advantech.com/en/support/details/firmware-?id=1-HIPU-183
Support options