CVE-2025-41442: Advantech iView Cross-site Scripting
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41442?
CVE-2025-41442 has a medium severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-41442?
To mitigate CVE-2025-41442, upgrade Advantech iView to version 5.7.05 build 7057 or later.
What types of attacks can CVE-2025-41442 allow?
CVE-2025-41442 can allow attackers to perform reflected cross-site scripting attacks, executing unauthorized scripts in a user's browser.
Which versions of Advantech iView are affected by CVE-2025-41442?
CVE-2025-41442 affects Advantech iView versions prior to 5.7.05 build 7057.
What input parameters are involved in CVE-2025-41442?
CVE-2025-41442 involves manipulation of specific input parameters that trigger the reflected cross-site scripting vulnerability.