CVE-2025-48891: Advantech iView SQL Injection
Published Jul 10, 2025
·Updated
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition.
Affected Software
3 affected components
Advantech iView
: Advantech iView: Versions prior to 5.7.05 build 7057
Advantech iView<5.7.05.7057
Remediation
Information
Advantech recommends users update to v5.7.05 build 7057 https://www.advantech.com/en/support/details/firmware- .
Event History
Jul 10, 2025
CVE Published
via MITRE·11:17 PM
Data Sourced
via MITRE·11:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via ICS·11:25 PM
SeverityWeaknessAffected Software
Jul 11, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48891?
CVE-2025-48891 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-48891?
To fix CVE-2025-48891, update Advantech iView to version 5.7.05 build 7057 or later.
3
What types of attacks can exploit CVE-2025-48891?
CVE-2025-48891 can be exploited to perform SQL injection attacks leading to potential information disclosure.
4
Who is affected by CVE-2025-48891?
CVE-2025-48891 affects all versions of Advantech iView prior to 5.7.05 build 7057.
5
What permissions are required to exploit CVE-2025-48891?
An authenticated attacker with at least user-level privileges can exploit CVE-2025-48891.