CVE-2025-53509

A vulnerability exists in Advantech iView that allows for argument 
injection in the NetworkServlet.restoreDatabase(). This issue requires 
an authenticated attacker with at least user-level privileges. An input 
parameter can be used directly in a command without proper sanitization,
 allowing arbitrary arguments to be injected. This can result in 
information disclosure, including sensitive database credentials.
Argument Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
icscertCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---