CVE-2025-52459: Advantech iView Argument Injection
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command without proper sanitization, allowing arbitrary arguments to be injected. This can result in information disclosure, including sensitive database credentials.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52459?
CVE-2025-52459 is classified as a high severity vulnerability that allows argument injection in Advantech iView.
How do I fix CVE-2025-52459?
To remediate CVE-2025-52459, upgrade Advantech iView to version 5.7.05 build 7057 or later.
Who is affected by CVE-2025-52459?
CVE-2025-52459 affects users of Advantech iView versions prior to 5.7.05 build 7057.
What type of attacker can exploit CVE-2025-52459?
CVE-2025-52459 can be exploited by an authenticated attacker with at least user-level privileges.
What are the consequences of exploiting CVE-2025-52459?
Exploitation of CVE-2025-52459 can lead to unauthorized command execution due to insufficient input sanitization.