We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.
Reserved 2025-07-02 | Published 2025-07-10 | Updated 2025-07-11 | Assigner icscertAlex Williams of Converge Technology Solutions reported these vulnerabilities to CISA.
www.cisa.gov/news-events/ics-advisories/icsa-25-191-08
www.advantech.com/en/support/details/firmware-?id=1-HIPU-183
Support options