📦 Iview

by Advantech

🔍 What is Iview?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-50591

CRITICAL CVSS 9.8 Nov 6, 2025

This vulnerability allows remote attackers to bypass authentication and execute SQL injection attacks on Advantech iView systems. Attackers can exfiltrate user data including clear text passwords. Org...

CVE-2022-50593

CRITICAL CVSS 9.8 Nov 6, 2025

This vulnerability allows remote attackers to bypass authentication and execute SQL injection via the SNMP management tool in Advantech iView, leading to remote code execution with administrator privi...

CVE-2022-2143

CRITICAL CVSS 9.8 Jul 22, 2022

CVE-2022-2143 is a critical command injection vulnerability in Advantech iView NetworkServlet that allows remote attackers to execute arbitrary code on affected systems. This affects industrial contro...

CVE-2021-22652

CRITICAL CVSS 9.8 Feb 11, 2021

CVE-2021-22652 is an unauthenticated remote code execution vulnerability in Advantech iView industrial monitoring software. Attackers can access configuration interfaces without credentials, modify se...

CVE-2021-22658

CRITICAL CVSS 9.8 Feb 11, 2021

CVE-2021-22658 is a SQL injection vulnerability in Advantech iView software that allows attackers to execute arbitrary SQL commands. Successful exploitation can lead to privilege escalation to Adminis...

CVE-2022-50595

HIGH CVSS 7.2 Nov 6, 2025

This vulnerability allows remote attackers to bypass authentication and execute SQL injection via the 'ztp_search_value' parameter in Advantech iView's SNMP management tool. Successful exploitation le...

CVE-2022-50592

HIGH CVSS 7.2 Nov 6, 2025

This vulnerability allows remote attackers to bypass authentication and execute SQL injection against Advantech iView's SNMP management tool. Successful exploitation leads to remote code execution wit...

CVE-2022-50594

HIGH CVSS 7.5 Nov 6, 2025

This vulnerability allows remote attackers to bypass authentication and execute SQL injection attacks on Advantech iView systems. Attackers can exfiltrate user data including clear-text passwords. Org...

CVE-2025-53515

HIGH CVSS 8.8 Jul 11, 2025

This vulnerability in Advantech iView allows authenticated attackers with user-level privileges to perform SQL injection through the NetworkServlet.archiveTrap() function, potentially leading to remot...

CVE-2025-53475

HIGH CVSS 8.8 Jul 11, 2025

This vulnerability in Advantech iView allows authenticated attackers with user-level privileges to perform SQL injection through the NetworkServlet.getNextTrapPage() function. Successful exploitation ...

CVE-2025-52577

HIGH CVSS 8.8 Jul 11, 2025

This vulnerability in Advantech iView allows authenticated attackers with user-level privileges to perform SQL injection through NetworkServlet.archiveTrapRange(), potentially leading to remote code e...

CVE-2025-48891

HIGH CVSS 7.6 Jul 11, 2025

An SQL injection vulnerability in Advantech iView's CUtils.checkSQLInjection() function allows authenticated attackers to execute arbitrary SQL commands. This affects systems running vulnerable versio...

CVE-2023-52335

HIGH CVSS 7.5 Nov 22, 2024

This SQL injection vulnerability in Advantech iView's ConfigurationServlet allows unauthenticated remote attackers to extract sensitive information like stored credentials from the database. All syste...

CVE-2023-3983

HIGH CVSS 8.8 Jul 31, 2023

An authenticated SQL injection vulnerability in Advantech iView allows authenticated attackers to bypass SQL injection checks and perform blind SQL injection attacks. This affects iView versions prior...

CVE-2022-2135

HIGH CVSS 7.5 Jul 22, 2022

CVE-2022-2135 is a SQL injection vulnerability in industrial control systems that allows unauthorized attackers to extract sensitive database information. This affects specific industrial software pro...

CVE-2022-2138

HIGH CVSS 8.2 Jul 22, 2022

This vulnerability allows attackers to bypass authentication in affected products, potentially enabling them to read or modify sensitive data, execute arbitrary code, or cause denial-of-service. It pr...

CVE-2022-2142

HIGH CVSS 8.1 Jul 22, 2022

This SQL injection vulnerability in industrial control systems allows unauthorized attackers to extract sensitive database information through crafted SQL queries. It affects specific industrial softw...

CVE-2021-32932

HIGH CVSS 7.5 Jun 11, 2021

This SQL injection vulnerability in Advantech iView allows attackers to execute arbitrary SQL commands on vulnerable systems. Unauthorized attackers can potentially access, modify, or delete database ...

CVE-2021-22656

HIGH CVSS 7.5 Feb 11, 2021

CVE-2021-22656 is a directory traversal vulnerability in Advantech iView that allows attackers to read sensitive files outside the intended directory. This affects organizations using Advantech iView ...

CVE-2025-41442

MEDIUM CVSS 5.4 Jul 11, 2025

A reflected cross-site scripting (XSS) vulnerability in Advantech iView allows attackers to inject malicious scripts via manipulated input parameters. This could lead to unauthorized script execution ...