Advantech
Advantech Iview: vulnerabilities and CVEs
Advantech Iview has 39 published vulnerabilities, 6 of them in the last 12 months. 14 are rated critical and 0 are listed by CISA as actively exploited.
CVEs39
Last 12 months6
Critical14
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13373 | High (8.7) | 0.44% | — | Dec 4, 2025 | Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands. |
| CVE-2022-50595 | Critical (9.3) | 0.63% | — | Nov 6, 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50594 | High (8.8) | 0.46% | — | Nov 6, 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50593 | Critical (9.3) | 0.69% | — | Nov 6, 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50592 | Critical (9.3) | 0.63% | — | Nov 6, 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50591 | High (8.8) | 0.50% | — | Nov 6, 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2025-53519 | Medium (5.1) | 0.21% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized… |
| CVE-2025-53515 | High (8.7) | 0.57% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges.… |
| CVE-2025-53509 | High (7.1) | 0.32% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter… |
| CVE-2025-53475 | High (8.7) | 6.1% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level… |
| CVE-2025-53397 | Medium (5.1) | 0.21% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in… |
| CVE-2025-52577 | High (8.7) | 0.57% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level… |
| CVE-2025-52459 | High (7.1) | 0.31% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can… |
| CVE-2025-48891 | High (7.2) | 0.29% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level… |
| CVE-2025-46704 | Medium (5.3) | 4.7% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A… |
| CVE-2025-41442 | Medium (5.1) | 0.21% | — | Jul 11, 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute… |
| CVE-2023-52335 | High (7.5) | 1.3% | — | Nov 22, 2024 | Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView.… |
| CVE-2023-3983 | High (8.8) | 17% | — | Jul 31, 2023 | An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform… |
| CVE-2022-3323 | High (7.5) | 29% | — | Sep 27, 2022 | An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a… |
| CVE-2022-2143 | Critical (9.8) | 59% | — | Jul 22, 2022 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. |
| CVE-2022-2142 | Medium (5.9) | 0.89% | — | Jul 22, 2022 | The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information. |
| CVE-2022-2139 | Critical (9.8) | 16% | — | Jul 22, 2022 | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code. |
| CVE-2022-2138 | High (7.5) | 11% | — | Jul 22, 2022 | The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition. |
| CVE-2022-2137 | Medium (4.9) | 0.94% | — | Jul 22, 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information |
| CVE-2022-2136 | Medium (6.5) | 9.1% | — | Jul 22, 2022 | The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information. |
| CVE-2022-2135 | High (7.5) | 10% | — | Jul 22, 2022 | The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information. |
| CVE-2021-32932 | High (7.5) | 1.2% | — | Jun 11, 2021 | The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182). |
| CVE-2021-32930 | Critical (9.8) | 8.1% | — | Jun 11, 2021 | The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182). |
| CVE-2021-22658 | Critical (9.8) | 13% | — | Feb 11, 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'. |
| CVE-2021-22656 | High (7.5) | 3.2% | — | Feb 11, 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files. |