CVE-2025-52577
published 2025-07-11CVE-2025-52577: A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.50%
39.0th percentile
A vulnerability exists in Advantech iView that could allow SQL injection
and remote code execution through NetworkServlet.archiveTrapRange().
This issue requires an authenticated attacker with at least user-level
privileges. Certain input parameters are not properly sanitized,
allowing an attacker to perform SQL injection and potentially execute
code in the context of the 'nt authority\local service' account.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advantech | iview | < 5.7.05 build 7057 | 5.7.05 build 7057 |
| advantech | iview | < 5.7.05.7057 | 5.7.05.7057 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle GoldenGate Risk Matrix: General (Apache Ignite) — CVE-2024-52577
vendor_oracle·2025-10-15·CVSS 9.8
CVE-2024-52577 [CRITICAL] Oracle Oracle GoldenGate Risk Matrix: General (Apache Ignite) — CVE-2024-52577
Oracle Oracle GoldenGate Risk Matrix: General (Apache Ignite) vulnerability
CVE: CVE-2024-52577
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
CISA ICS
Advantech iView
cisa_ics·2025-07-10·CVSS 5.4
[MEDIUM] Advantech iView
ICS Advisory
##
Advantech iView
Release DateJuly 10, 2025
Alert CodeICSA-25-191-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Advantech
- Equipment: iView
- Vulnerabilities: Cross-site Scripting, SQL Injection, Path Traversal, Argument Injection.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, achieve remote code execution, or cause service disruptions.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Advantech products are affected:
- iView: Versions prior to 5.7.05 build 7057
## 3.2 VULNERABILITY O
GHSA
GHSA-5fv5-hvwx-g2h9: A vulnerability exists in Advantech iView that could allow SQL injection
and remote code execution through NetworkServlet
ghsa_unreviewed·2025-07-11
CVE-2025-52577 [HIGH] CWE-89 GHSA-5fv5-hvwx-g2h9: A vulnerability exists in Advantech iView that could allow SQL injection
and remote code execution through NetworkServlet
A vulnerability exists in Advantech iView that could allow SQL injection
and remote code execution through NetworkServlet.archiveTrapRange().
This issue requires an authenticated attacker with at least user-level
privileges. Certain input parameters are not properly sanitized,
allowing an attacker to perform SQL injection and potentially execute
code in the context of the 'nt authority\local service' account.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-11
Published