CVE-2025-53519

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:*

History

23 Jul 2025, 19:19

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-08 - US Government Resource
References () https://www.advantech.com/en/support/details/firmware-?id=1-HIPU-183 - () https://www.advantech.com/en/support/details/firmware-?id=1-HIPU-183 - Product, Release Notes
CPE cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:*
First Time Advantech
Advantech iview

11 Jul 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 00:15

Updated : 2025-07-23 19:19


NVD link : CVE-2025-53519

Mitre link : CVE-2025-53519


JSON object : View

Products Affected

advantech

  • iview
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')