CVE-2022-50591: Advantech Iview
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
Affected products
- Advantech Iview: before 5.7.04.6425 (fixed in 5.7.04.6425)
Published 2025-11-06. Last modified 2026-06-17.