CVE-2025-52577: Advantech iView SQL Injection
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52577?
CVE-2025-52577 has a high severity rating due to the potential for SQL injection and remote code execution.
What products are affected by CVE-2025-52577?
CVE-2025-52577 affects Advantech iView versions prior to 5.7.05 build 7057.
How do I fix CVE-2025-52577?
To fix CVE-2025-52577, upgrade to Advantech iView version 5.7.05 build 7057 or later.
Who can exploit CVE-2025-52577?
CVE-2025-52577 can be exploited by authenticated attackers with at least user-level privileges.
What are the implications of CVE-2025-52577 on system security?
CVE-2025-52577 may allow an attacker to execute arbitrary code, compromising system integrity and data security.