CVE-2025-53475

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
11/07/2025
Last modified:
11/07/2025

Description

A vulnerability exists in Advantech iView that could allow for SQL <br /> injection and remote code execution through <br /> NetworkServlet.getNextTrapPage(). This issue requires an authenticated <br /> attacker with at least user-level privileges. Certain parameters in this<br /> function are not properly sanitized, allowing an attacker to perform <br /> SQL injection and potentially execute code in the context of the &amp;#39;nt <br /> authority\local service&amp;#39; account.