CVE-2025-46704

A vulnerability exists in Advantech iView in 
NetworkServlet.processImportRequest() that could allow for a directory 
traversal attack. This issue requires an authenticated attacker with at 
least user-level privileges. A specific parameter is not properly 
sanitized or normalized, potentially allowing an attacker to determine 
the existence of arbitrary files on the server.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
icscertCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---