CVE-2025-52459

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/07/2025
Last modified:
11/07/2025

Description

A vulnerability exists in Advantech iView that allows for argument <br /> injection in NetworkServlet.backupDatabase(). This issue requires an <br /> authenticated attacker with at least user-level privileges. Certain <br /> parameters can be used directly in a command without proper <br /> sanitization, allowing arbitrary arguments to be injected. This can <br /> result in information disclosure, including sensitive database <br /> credentials.