CVE-2025-41442

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:*

History

23 Jul 2025, 19:20

Type Values Removed Values Added
CPE cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:*
References () https://www.advantech.com/en/support/details/firmware-?id=1-HIPU-183 - () https://www.advantech.com/en/support/details/firmware-?id=1-HIPU-183 - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08 - Third Party Advisory, US Government Resource
First Time Advantech
Advantech iview

11 Jul 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad en las versiones de Advantech iView anteriores a la 5.7.05, compilación 7057, que podría permitir un ataque de cross-site scripting (XSS) reflejado. Al manipular ciertos parámetros de entrada, un atacante podría ejecutar secuencias de comandos no autorizadas en el navegador del usuario, lo que podría provocar la divulgación de información u otras actividades maliciosas.

11 Jul 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 00:15

Updated : 2025-07-23 19:20


NVD link : CVE-2025-41442

Mitre link : CVE-2025-41442

CVE.ORG link : CVE-2025-41442


JSON object : View

Products Affected

advantech

  • iview
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')