CVE-2025-53515

A vulnerability exists in Advantech iView that allows for SQL injection 
and remote code execution through NetworkServlet.archiveTrap(). This 
issue requires an authenticated attacker with at least user-level 
privileges. Certain input parameters are not sanitized, allowing an 
attacker to perform SQL injection and potentially execute code in the 
context of the 'nt authority\local service' account.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
icscertCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---