A vulnerability exists in Advantech iView that allows for SQL injection
and remote code execution through NetworkServlet.archiveTrap(). This
issue requires an authenticated attacker with at least user-level
privileges. Certain input parameters are not sanitized, allowing an
attacker to perform SQL injection and potentially execute code in the
context of the 'nt authority\local service' account.
References
Configurations
No configuration.
History
15 Jul 2025, 13:14
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-11 00:15
Updated : 2025-07-15 13:14
NVD link : CVE-2025-53515
Mitre link : CVE-2025-53515
CVE.ORG link : CVE-2025-53515
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')