← Vulnerability feed

Vulnerability record · CVE-2020-14505 · published 15 July 2020

CVE-2020-14505: Advantech iview command injection vulnerability

Advantech · Iview

Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.

9.8 CVSS 3.1 Critical EPSS 7.0% · top 6.0% CWE-77 · Command injectionCWE-74 · Injection
9.8CVSS 3.1 base score, v2 7.5
7.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14505 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-2139Advantech iview relative path traversal vulnerabilityThe affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.EPSS 16%9.8CVE-2022-2143Advantech iView command injection in NetworkServletAdvantech iView contains two command injection flaws (CWE-77) that let an attacker run arbitrary commands on the host. The vulnerability is remotely …EPSS 59%analysed9.8CVE-2021-32930Advantech iview missing authentication for critical function vulnerabilityThe affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar…EPSS 8.1%9.8CVE-2021-22652Advantech iview missing authentication for critical function vulnerabilityAccess to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to ch…EPSS 37%9.8CVE-2021-22658Advantech iview sql injection vulnerabilityAdvantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrato…EPSS 13%9.8CVE-2020-16245Advantech iview path traversal vulnerabilityAdvantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/…EPSS 7.7%9.8CVE-2020-14501Advantech iview missing authentication for critical function vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulner…EPSS 1.7%9.8CVE-2020-14503Advantech iview improper input validation vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an…EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2020-14505), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.