8.8

CVSS4.0

CVE-2022-50591 - Advantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information Disclosure

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exp…

📅 Published: Nov. 6, 2025, 7:58 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:58 p.m.

9.3

CVSS4.0

CVE-2022-50593 - Advantech iView < v5.7.04 Build 6425 search_term Parameter SQL Injection RCE

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful explo…

📅 Published: Nov. 6, 2025, 7:57 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:57 p.m.

9.3

CVSS4.0

CVE-2022-50592 - Advantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCE

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Succe…

📅 Published: Nov. 6, 2025, 7:57 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:57 p.m.

8.8

CVSS4.0

CVE-2022-50594 - Advantech iView < v5.7.04 Build 6425 data Parameter SQL Injection Information Disclosure

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation…

📅 Published: Nov. 6, 2025, 7:57 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:57 p.m.

5.1

CVSS4.0

CVE-2025-34247 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via NetworksController.addNetworkAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:49 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:49 p.m.

5.3

CVSS4.0

CVE-2025-34246 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxPrevalidationController.ajaxAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:49 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:49 p.m.

5.3

CVSS4.0

CVE-2025-34245 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxStandaloneVpnClientsController.ajaxAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:48 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:48 p.m.

5.3

CVSS4.0

CVE-2025-34244 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxDeviceFwRulesAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:47 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:47 p.m.

5.3

CVSS4.0

CVE-2025-34243 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxNetworkFwRulesAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:47 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:47 p.m.

8.6

CVSS4.0

CVE-2025-34242 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxNetworkController.ajaxAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:46 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:46 p.m.
Total resulsts: 317293
Page 7 of 31,730
« previous page » next page
Filters