Back to search
CVE-2022-50591
Published: Nov 6, 2025
Modified: Nov 15, 2025
PUBLISHED
Description
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
| Vendor | Product | Versions |
|---|---|---|
Advantech | iView | affected 0 - < 5.7.04 build 6425 |
References
https://www.advantech.tw/support/details/firmware?id=1-HIPU-183
release-notes
patch
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now