Security Advisory

CVE-2025-53475

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-10 23:23:38
Last updated 2025-07-11 13:39:39
Assigner icscert
CVSS score not scored
State PUBLISHED

Description

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.