CVE-2025-13373: Advantech iView SQL Injection
Published Dec 4, 2025
·Updated
Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.
Affected Software
2 affected components
Advantech iView<5.7.05.7057
: Advantech iView=5.7.05.7057
Remediation
Information
Advantech recommends users update to iView v5.8.1 https://www.advantech.com/zh-tw/support/details/firmware .
Event History
Dec 4, 2025
CVE Published
via MITRE·10:50 PM
Data Sourced
via MITRE·10:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via ICS·11:01 PM
SeverityWeaknessAffected Software
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-13373?
CVE-2025-13373 has a high severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2025-13373?
To fix CVE-2025-13373, update Advantech iView to version 5.7.05.7058 or later.
3
What systems are affected by CVE-2025-13373?
CVE-2025-13373 affects Advantech iView versions 5.7.05.7057 and earlier.
4
What kind of attack can exploit CVE-2025-13373?
An attacker can exploit CVE-2025-13373 by injecting SQL commands through improperly sanitized SNMP v1 trap requests.
5
Is CVE-2025-13373 being actively exploited?
There are indications that CVE-2025-13373 may be subject to active exploitation in the wild.