CVE-2025-53475

A vulnerability exists in Advantech iView that could allow for SQL 
injection and remote code execution through 
NetworkServlet.getNextTrapPage(). This issue requires an authenticated 
attacker with at least user-level privileges. Certain parameters in this
 function are not properly sanitized, allowing an attacker to perform 
SQL injection and potentially execute code in the context of the 'nt 
authority\local service' account.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
icscertCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---