SQL Injection Vulnerability in Advantech iView
CVE-2025-48891

7.2HIGH

Key Information:

Vendor

Advantech

Status
Vendor
CVE Published:
11 July 2025

What is CVE-2025-48891?

A security flaw in Advantech iView has been identified, which enables SQL injection through the CUtils.checkSQLInjection() function. If successfully exploited by an authenticated user with minimum privileges, this vulnerability can lead to significant risks, including unauthorized information disclosure and possible denial-of-service effects. Users of Advantech iView should take immediate action to address this security issue.

Affected Version(s)

iView 0 < 5.7.05 build 7057

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.