Critical severity9.8NVD Advisory· Published Nov 6, 2025· Updated Jun 17, 2026
CVE-2022-50591
CVE-2022-50591
Description
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- blog.exodusintel.com/2022/03/01/advantech-iview-ztp_config_id-parameter-sql-injection-information-disclosure-vulnerability/nvdThird Party Advisory
- www.advantech.tw/support/details/firmwarenvdVendor Advisory
- www.vulncheck.com/advisories/advantech-iview-ztpconfigid-parameter-sqli-information-disclosurenvdThird Party Advisory
News mentions
0No linked articles in our index yet.