CVE-2025-53515
Last modified
CVE-2025-53515 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Iview | < 5.7.05.7057 |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-53515?
How severe is CVE-2025-53515?
How do I fix CVE-2025-53515?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-5351A flaw was found in the key export functionality of libssh. …6.5
- CVE-2025-53510A memory corruption vulnerability exists in the PSD Image De…8.8
- CVE-2025-53511A heap-based buffer overflow vulnerability exists in the MFE…9.8
- CVE-2025-53512The /log endpoint on a Juju controller lacked sufficient aut…6.5
- CVE-2025-53513The /charms endpoint on a Juju controller lacked sufficient …6.5
- CVE-2025-53514Mattermost Confluence Plugin version <1.5.0 fails to handle …5.9
- CVE-2025-53516A reflected cross-site scripting (xss) vulnerability exists …6.1
- CVE-2025-53517Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-53518An integer overflow vulnerability exists in the ABF parsing …9.8
- CVE-2025-53519A vulnerability exists in Advantech iView versions prior to …5.4
- CVE-2025-5352A critical stored Cross-Site Scripting (XSS) vulnerability e…9.6
- CVE-2025-53520The affected product allows firmware updates to be downloade…8.8
Are you affected by CVE-2025-53515?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
