CVE-2025-46704

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or normalized, potentially allowing an attacker to determine the existence of arbitrary files on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:*

History

23 Jul 2025, 19:20

Type Values Removed Values Added
CPE cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:*
References () https://www.advantech.com/en/support/details/firmware-?id=1-HIPU-183 - () https://www.advantech.com/en/support/details/firmware-?id=1-HIPU-183 - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08 - Third Party Advisory, US Government Resource
First Time Advantech
Advantech iview

11 Jul 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad en Advantech iView en NetworkServlet.processImportRequest() que podría permitir un ataque de salto de directorio. Este problema requiere un atacante autenticado con al menos privilegios de usuario. Un parámetro específico no está correctamente depurado ni normalizado, lo que podría permitir que un atacante determine la existencia de archivos arbitrarios en el servidor.

11 Jul 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 00:15

Updated : 2025-07-23 19:20


NVD link : CVE-2025-46704

Mitre link : CVE-2025-46704

CVE.ORG link : CVE-2025-46704


JSON object : View

Products Affected

advantech

  • iview
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')