CVE-2025-52459

A vulnerability exists in Advantech iView that allows for argument 
injection in NetworkServlet.backupDatabase(). This issue requires an 
authenticated attacker with at least user-level privileges. Certain 
parameters can be used directly in a command without proper 
sanitization, allowing arbitrary arguments to be injected. This can 
result in information disclosure, including sensitive database 
credentials.
Argument Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
icscertCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---