CVE-2025-46704: Advantech iView Path Traversal
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or normalized, potentially allowing an attacker to determine the existence of arbitrary files on the server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46704?
CVE-2025-46704 has a high severity rating due to its potential for directory traversal attacks.
How do I fix CVE-2025-46704?
To fix CVE-2025-46704, update Advantech iView to versions 5.7.05 build 7057 or later.
Who is affected by CVE-2025-46704?
CVE-2025-46704 affects users of Advantech iView versions prior to 5.7.05 build 7057.
Can CVE-2025-46704 be exploited without authentication?
No, CVE-2025-46704 requires an authenticated attacker with at least user-level privileges to be exploited.
What type of attack does CVE-2025-46704 allow?
CVE-2025-46704 allows for directory traversal attacks due to improper sanitization of a specific parameter.