References https://www.cisa.gov/news-events/ics-advisories/icsa-22-179-03 https://www.zerodayinitiative.com/advisories/ZDI-22-919/ https://www.cve.org/CVERecord?id=CVE-2022-2135 https://nvd.nist.gov/vuln/detail/cve-2022-2135 https://www.sonicwall.com/blog/advantech-iview-sql-injection-vulnerability https://www.tenable.com/security/research/tra-2023-24 https://app.opencve.io/cve/?product=iview&vendor=advantech https://advisories.checkpoint.com/defense/advisories/public/2022/cpai-2022-0762.html https://github.com/advisories/GHSA-g2xr-8jgc-jrmr https://blog.exodusintel.com/2022/03/01/advantech-iview-page_action_service-parameter-sql-injection-remote-code-execution-vulnerability https://db.gcve.eu/vuln/gsd-2022-2135 https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2022-2135 https://www.tenable.com/security/research/tra-2022-32 https://cve.imfht.com/detail/CVE-2022-2135 https://jvn.jp/vu/JVNVU97814223/index.html https://euvd.enisa.europa.eu/advisory/ICSA-22-179-03 https://cve.yack.one/vendors/advantech?offset=100&limit=20 https://www.vulncheck.com/advisories/advantech-iview-searchterm-parameter-sqli-rce https://stack.watch/vuln/CVE-2022-2135/ https://docs.sophos.com/releasenotes/output/en-us/nsg/IPSReleaseNotes/7.19.66_s.pdf https://avd.aliyun.com/product?prod=iview
Related VulnerabilitiesPoCCVE-2025-52694: Advantech WISE-IoTSuite/SaaS - SQL InjectionPoCCVE-2021-21799: Advantech R-SeeNet 2.4.12 - Cross-Site ScriptingPoCCVE-2021-21800: Advantech R-SeeNet 2.4.12 - Cross-Site ScriptingPoCCVE-2021-21801: Advantech R-SeeNet - Cross-Site ScriptingPoCCVE-2021-21802: Advantech R-SeeNet - Cross-Site ScriptingPoCCVE-2021-21803: Advantech R-SeeNet - Cross-Site ScriptingPoCCVE-2021-21805: Advantech R-SeeNet 2.4.12 - OS Command InjectionPoCCVE-2024-3850: Uniview NVR301-04S2-P4 - Cross-Site ScriptingPoCrseenet-default-password: Advantech R-SeeNet Default LoginPoCuniview-isc-logreport-php-rce: 浙江宇视科技 网络视频录像机 ISC LogReport.php 远程命令执行漏洞PoCrseenet-default-login: Advantech R-SeeNet Default Login宇视科技 Uniview /Interface/DevManage/VM.php 命令注入漏洞浙江宇视科技 uniview 弱口令漏洞