← Vulnerability feed

Vulnerability record · CVE-2022-50593 · published 6 November 2025

CVE-2022-50593: Advantech iview sql injection vulnerability

Advantech · Iview

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

9.3 CVSS 4.0 Critical EPSS 0.69% · top 49.3% CWE-89 · SQL injectionCWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-50593 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-2139Advantech iview relative path traversal vulnerabilityThe affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.EPSS 16%9.8CVE-2022-2143Advantech iView command injection in NetworkServletAdvantech iView contains two command injection flaws (CWE-77) that let an attacker run arbitrary commands on the host. The vulnerability is remotely …EPSS 59%analysed9.8CVE-2021-32930Advantech iview missing authentication for critical function vulnerabilityThe affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar…EPSS 8.1%9.8CVE-2021-22652Advantech iview missing authentication for critical function vulnerabilityAccess to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to ch…EPSS 37%9.8CVE-2021-22658Advantech iview sql injection vulnerabilityAdvantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrato…EPSS 13%9.8CVE-2020-16245Advantech iview path traversal vulnerabilityAdvantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/…EPSS 7.7%9.8CVE-2020-14501Advantech iview missing authentication for critical function vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulner…EPSS 1.7%9.8CVE-2020-14503Advantech iview improper input validation vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an…EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2022-50593), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.