Advantech System Integration services HW/SW
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Advantech product.
RSS Feeds for Advantech security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Advantech products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Advantech Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 13 vulnerabilities in Advantech with an average score of 7.8 out of ten. Last year, in 2025 Advantech had 49 security vulnerabilities published. Right now, Advantech is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.43.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 13 | 7.76 |
| 2025 | 49 | 6.33 |
| 2024 | 7 | 7.10 |
| 2023 | 10 | 8.84 |
| 2022 | 15 | 7.90 |
| 2021 | 62 | 7.32 |
| 2020 | 28 | 8.45 |
| 2019 | 31 | 9.23 |
| 2018 | 28 | 7.18 |
It may take a day or so for new Advantech vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Advantech Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-43833 | Jul 31, 2026 |
Authn Stack Buffer Overflow in Upload (CVE-2026-43833)Full details and mitigation steps are currently restricted and will be published at a later date. |
|
| CVE-2026-43832 | Jul 31, 2026 |
Stack Buffer Overflow in Cookie Parsing with SafeEnhancementFull details and mitigation steps are currently restricted and will be published at a later date. |
|
| CVE-2026-43831 | Jul 31, 2026 |
Unauthenticated Stack BufOverflow in log msg enabling code execFull details and mitigation steps are currently restricted and will be published at a later date. |
|
| CVE-2026-43830 | Jul 31, 2026 |
Firmware Upgrade File Verification Command Injection (CVE-2026-43830)Full details and mitigation steps are currently restricted and will be published at a later date. |
|
| CVE-2026-43829 | Jul 31, 2026 |
Unauthenticated Stack-Based Buffer Overflow in SafeEnhancement Password FeatureFull details and mitigation steps are currently restricted and will be published at a later date. |
|
| CVE-2026-6890 | Jul 31, 2026 |
Default root SSH creds in Advantech ECU-1251D IoT device |
|
| CVE-2026-6889 | Jul 31, 2026 |
DNP3 Daemon DoS via Null File on Advantech ECU-1251D |
|
| CVE-2026-14162 | Jun 30, 2026 |
Advantech Hospital Queuing Mgmt APIDoc Endpoint Exposes Sensitive DataHospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation. |
|
| CVE-2026-14161 | Jun 30, 2026 |
Advantech Hospital Quening Mgmt SDE via API Docs URLHospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation. |
|
| CVE-2026-36226 | May 22, 2026 |
CrossSite Scripting in Advantech WebAccess/SCADA 8.0-2015.08.16 via decryption fieldCross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component |
|
| CVE-2026-6888 | May 13, 2026 |
Auth SQLi Exec Arbitrary Cmd via InterfaceSuccessful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database. |
|
| CVE-2026-2670 | Feb 18, 2026 |
OS Command Injection Advantech WISE-6610 1.2.1_20251110 openvpn_applyA vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. |
|
| CVE-2025-52694 | Jan 12, 2026 |
SQLi Remote Exec in Unknown Web ServiceSuccessful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately. |
|
| CVE-2025-67653 | Dec 18, 2025 |
Advantech WebAccess/SCADA Directory Traversal (CVE-2025-67653)Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files. |
|
| CVE-2025-46268 | Dec 18, 2025 |
SQLi in Advantech WebAccess/SCADAAdvantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands. |
|
| CVE-2025-14848 | Dec 18, 2025 |
Advantech WebAccess/SCADA Abs Dir TraversalAdvantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files. |
|
| CVE-2025-14849 | Dec 18, 2025 |
Advantech WebAccess SCADA Unrestricted File Upload Allowing Remote Code ExecAdvantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. |
|
| CVE-2025-14850 | Dec 18, 2025 |
Dir Traversal in Advantech WebAccess/SCADA Allows Arbitrary File DeletionAdvantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files. |
|
| CVE-2025-14252 | Dec 16, 2025 |
Priv Esc in Advantech SUSI Driver 5.0.24335 via Improper AccessAn Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior. |
|
| CVE-2025-34256 | Dec 05, 2025 |
Advantech WISE-DeviceOn 5.4- HS512 HMAC Key Hard-coded JWT ForgeAdvantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOns remote management features. |
|
| CVE-2025-34265 | Dec 05, 2025 |
Stored XSS in Advantech WISE-DeviceOn Server rmm/v1/rule-engines (5.3)Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings or detail views without proper HTML sanitation. An attacker can inject malicious script into one or more of these fields, which is then executed in the browser context of users who view or interact with the affected rule, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34263 | Dec 05, 2025 |
Advantech WISE-DeviceOn Server <5.4 XSS via /rmm/v1/plugin-config/dashboards/menusAdvantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin configuration data and later rendered in the dashboard UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected dashboard, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34266 | Dec 05, 2025 |
Advantech WISE-DeviceOn Server <5.4 XSS via /rmm/v1/plugin-config/addins/menusAdvantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and later rendered in the AddIns UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected AddIns entry, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34264 | Dec 05, 2025 |
Advantech WISE-DeviceOn Server <=5.4: XSS in Software Watchdog UIAdvantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34262 | Dec 05, 2025 |
Advantech WISE-DeviceOn <5.4 Stored XSS in /rmm/v1/devices/name/{agent_id}Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without proper HTML sanitation. An attacker can inject malicious script into the device name, which is then executed in the browser context of users who view or interact with the affected device, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34258 | Dec 05, 2025 |
Advantech WISE-DeviceOn Server <5.4 XSS in /rmm/v1/devicemap/planAdvantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. An attacker can inject malicious script into the area name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34259 | Dec 05, 2025 |
Advantech WISE-DeviceOn XSS in /devicemap/building (pre-5.4)Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without HTML sanitzation. An attacker can inject malicious script into the map entry name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34261 | Dec 05, 2025 |
XSS in Advantech WISE-DeviceOn Server <5.4 via /rmm/v1/devicegroups/Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected device group, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34260 | Dec 05, 2025 |
Advantech WISE-DeviceOn Server <5.4 XSS via /rmm/v1/action/scheduleAdvantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sanitation. An attacker can inject malicious script into the schedule name, which is then executed in the browser context of users who view or interact with the affected schedule, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-34257 | Dec 05, 2025 |
Advantech WISE-DeviceOn Server <=5.3 XSS via /rmm/v1/action/definedAdvantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim. |
|
| CVE-2025-13373 | Dec 04, 2025 |
Advantech iView <=5.7.05.7057 SQL injection via SNMP v1 trap (Port 162)Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands. |
|
| CVE-2025-58423 | Nov 06, 2025 |
Insufficient Sanitization in File Upload Enables Path Traversal, File Access and DOS (CVE-2025-58423Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account. |
|
| CVE-2025-59171 | Nov 06, 2025 |
RCE via Unsanitized Config File Upload and Directory TraversalDue to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions. |
|
| CVE-2025-62630 | Nov 06, 2025 |
Unsanitized Config File Upload Enables Directory Traversal RCEDue to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions. |
|
| CVE-2025-64302 | Nov 06, 2025 |
CVE-2025-64302: Dashboard Label/Path Injection Causing Device ErrorInsufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation. |
|
| CVE-2022-50595 | Nov 06, 2025 |
Advantech iView <=5.7.04 SNMP Auth Bypass + SQLi RCEAdvantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ztp_search_value parameter to the NetworkServlet endpoint. Successful exploitation allows for remote code execution with administrator privileges. |
|
| CVE-2022-50591 | Nov 06, 2025 |
Advantech iView <5.7.04 SQL injection via SNMPAdvantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ztp_config_id parameter to the NetworkServlet endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords. |
|
| CVE-2022-50593 | Nov 06, 2025 |
Advantech iView <5.7.04: SNMP Auth Bypass + SQLi RCEAdvantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the search_term parameter to the NetworkServlet endpoint. Successful exploitation allows for remote code execution with administrator privileges. |
|
| CVE-2022-50592 | Nov 06, 2025 |
Advantech iView before v5.7.04: SNMP Auth Bypass + SQLi RCEAdvantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the getInventoryReportData parameter to the NetworkServlet endpoint. Successful exploitation allows for remote code execution with administrator privileges. |
|
| CVE-2022-50594 | Nov 06, 2025 |
Advantech iView <=5.7.04 SNMP Auth Bypass + SQLi in NetworkServletAdvantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the data parameter to the NetworkServlet endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords. |
|
| CVE-2025-34247 | Nov 06, 2025 |
Advantech WebAccess VPN 1.1.5 SQLi via NetworksController.addNetworkAction()Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34246 | Nov 06, 2025 |
Advantech WebAccess/VPN <1.1.5: SQLi via AjaxPrevalidationControllerAdvantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34245 | Nov 06, 2025 |
Advantech WebAccess/VPN SQLi prior to 1.1.5 via AjaxStandaloneVpnClientsControllerAdvantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34244 | Nov 06, 2025 |
SQLi in Advantech WebAccess/VPN <1.1.5 via AjaxFwRulesControllerAdvantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34243 | Nov 06, 2025 |
SQLi in Advantech WebAccess/VPN <1.1.5 via AjaxFwRulesControllerAdvantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34242 | Nov 06, 2025 |
Advantech WebAccess/VPN <=1.1.4: Auth observer SQLi via AjaxNetworkControllerAdvantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34241 | Nov 06, 2025 |
Advantech WebAccess/VPN <=1.1.4: SQLi in AjaxDeviceControllerAdvantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34240 | Nov 06, 2025 |
SQLi via AuthObs in Advantech WebAcc/VPN <1.1.5 AppMgmtCtrl.appUpgradeAction()Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information. |
|
| CVE-2025-34239 | Nov 06, 2025 |
Advantech WebAccess/VPN <1.1.5: Auth Cmd Injection via AppMgmtCtrlAdvantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename. |
|
| CVE-2025-34238 | Nov 06, 2025 |
Advantech WebAccess/VPN <1.1.5: Authenticated Path Traversal ExploitAdvantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web user (www-data) can access. |
|