CVE-2025-52459 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker…
High CVSS: 7.1

CVE-2025-52459

A vulnerability exists in Advantech iView that allows for argument
injection in NetworkServlet.backupDatabase(). This issue requires an
authenticated attacker with at least user-level privileges. Certain
parameters can be used directly in a command without proper
sanitization, allowing arbitrary arguments to be injected. This can
result in information disclosure, including sensitive database
credentials.
Vendor
-
Product
-
CWE
CWE-88
Yayın Tarihi
2025-07-11 00:15:26
Güncelleme
2025-07-15 13:14:49
Source Identifier
ics-cert@hq.dhs.gov
KEV Date Added
-

Kategoriler

Referanslar