CVE-2025-13373

7.5

Advantech · iView

Advantech iView versions 5.7.05.7057 and prior are vulnerable to SQL injection via unsanitized SNMP v1 trap requests on port 162.

Executive summary

An unauthenticated SQL injection vulnerability in Advantech iView 5.7.05.7057 and prior allows remote attackers to execute arbitrary database commands.

Vulnerability

This vulnerability involves improper neutralization of special elements used in SQL commands (CWE-89). Unauthenticated attackers can trigger the flaw by sending malicious SNMP v1 trap requests to port 162.

Business impact

The ability to perform SQL injection against a network management platform presents a significant risk to data confidentiality. Successful exploitation could allow an attacker to extract sensitive system information, potentially leading to unauthorized access to the underlying management infrastructure and broader network compromise. Given the CVSS score of 7.5, this is classified as a High severity issue requiring immediate attention to prevent data exfiltration.

Remediation

Immediate Action: Update Advantech iView to version 5.8.1 or later as specified in the vendor advisory.

Proactive Monitoring: Review system logs for unusual SNMP traffic patterns or malformed SNMP trap requests originating from untrusted sources.

Compensating Controls: Restrict access to UDP port 162 to known, trusted management stations using network segmentation or firewall rules to prevent unauthorized SNMP trap submission.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability represents a critical risk to industrial control and network management environments. Organizations utilizing Advantech iView should prioritize the transition to version 5.8.1 to eliminate the SQL injection vector. Until the update is applied, strict network access control lists for SNMP traffic are essential to mitigate the risk of remote command execution.

More Advantech CVEs

Sources

Originally found and disclosed by m00nback reported this vulnerability to CISA., per the CVE Program record.