HIGH
Advantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information Disclosure
Published Nov 6, 2025
8.8
HIGHCVSS 4.0
EPSS 0.53%
Description
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
Affected products
-
Affected
- ≥ 0, < 5.7.04 build 6425
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://blog.exodusintel.com/2022/03/01/advantech-iview-ztp_config_id-parameter-sql-injection-information-disclosure-vulnerability/ technical-descriptionThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-38181 Advisory
- https://www.advantech.tw/support/details/firmware?id=1-HIPU-183 release-notespatchVendor Advisory
- https://www.vulncheck.com/advisories/advantech-iview-ztpconfigid-parameter-sqli-information-disclosure third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.exodusintel.com/2022/03/01/advantech-iview-ztp_config_id-parameter-sql-injection-information-disclosure-vulnerability/ | technical-descriptionThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-38181 | Advisory | |
| https://www.advantech.tw/support/details/firmware?id=1-HIPU-183 | release-notespatchVendor Advisory | |
| https://www.vulncheck.com/advisories/advantech-iview-ztpconfigid-parameter-sqli-information-disclosure | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Nov 6, 2025
Updated Nov 15, 2025
Reserved Nov 5, 2025
Link CVE-2022-50591
CISA Vulnrichment
Updated Nov 6, 2025
Red Hat
No data
GitHub
No data