Advantech Advantech System Integration services HW/SW

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Advantech product.

RSS Feeds for Advantech security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Advantech products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Advantech Sorted by Most Security Vulnerabilities since 2018

Advantech Webaccess89 vulnerabilities

Advantech Iview33 vulnerabilities

Advantech Webaccessscada29 vulnerabilities

Advantech Webaccess Scada18 vulnerabilities

Advantech Webaccessvpn12 vulnerabilities

Advantech Wise Deviceon Server11 vulnerabilities

Advantech Deviceon Iedge4 vulnerabilities

Advantech Adam 5630 Firmware3 vulnerabilities

Advantech Wise 6610p Dta3 vulnerabilities

Advantech Wise 6610p Dna3 vulnerabilities

Advantech Wise 6610p Dea3 vulnerabilities

Advantech Wise 6610 Tb3 vulnerabilities

Advantech Wise 6610 Nb3 vulnerabilities

Advantech Wise 6610 Jb3 vulnerabilities

Advantech Wise 6610 El Tb3 vulnerabilities

Advantech Wise 6610 El Nb3 vulnerabilities

Advantech Wise 6610 El Jb3 vulnerabilities

Advantech Wise 6610 El Eb3 vulnerabilities

Advantech Wise 6610 El Cb3 vulnerabilities

Advantech Wise 6610 Eb3 vulnerabilities

Advantech Wise 6610 Cb3 vulnerabilities

Advantech Adam 5550 Firmware2 vulnerabilities

Advantech Adam 60521 vulnerability

Advantech Adam 60661 vulnerability

Advantech Adam 65011 vulnerability

Advantech Adam 60151 vulnerability

Advantech Adam 6060w1 vulnerability

Advantech Adam 60601 vulnerability

Advantech Adam 60181 vulnerability

Advantech Adam 6051w1 vulnerability

Advantech Adam 60511 vulnerability

Advantech Adam 6050w1 vulnerability

Advantech Adam 60501 vulnerability

Advantech Adam 60241 vulnerability

Advantech Adam 60221 vulnerability

Advantech Adam 60171 vulnerability

By the Year

In 2026 there have been 30 vulnerabilities in Advantech with an average score of 8.3 out of ten. Last year, in 2025 Advantech had 49 security vulnerabilities published. Right now, Advantech is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.94.




Year Vulnerabilities Average Score
2026 30 8.28
2025 49 6.33
2024 7 7.10
2023 10 8.84
2022 15 7.90
2021 62 7.32
2020 28 8.45
2019 31 9.23
2018 28 7.18

It may take a day or so for new Advantech vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Advantech Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-73177 Sep 16, 2026
Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01 Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.
CVE-2026-73176 Sep 16, 2026
Advantech EKI-1242IEIMS V1.06.01 OS Command Injection via Web UI Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
CVE-2026-73175 Sep 16, 2026
Advantech EKI-1242EIMS V1.06.01 OPC UA Gateway DoS (CWE-400) Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.
CVE-2026-73174 Sep 16, 2026
Advantech EKI-1242EIMS Cleartext Leak via edgserver (CWE-319) V1.06.01 Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.
CVE-2026-73173 Sep 16, 2026
Advantech EKI-1242EIMS v1.06.01 Remote AuthBypass in edgserver (TCP 5058) Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.
CVE-2026-73172 Sep 16, 2026
Advantech EKI-1242EIMS 1.06.01 OS Command Injection via edgserver (port 5058) Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.
CVE-2026-73171 Sep 16, 2026
CWE-73 Path Traversal in Advantech EKI-1242EIMS V1.06.01 via Web Upload Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.
CVE-2026-73170 Sep 16, 2026
Advantech EKI-1242EIMS v1.06.01 - Lua Code Injection via CSV Import (CWE-94) Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.
CVE-2026-73169 Sep 16, 2026
Advantech EKI-1242EIMS V1.06.01 XSS in Modbus Tx mgmt interface (CWE79) Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page.
CVE-2026-73167 Sep 16, 2026
Advantech EKI-1242IEIMS 1.06.01 OS Command Injection Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
CVE-2026-73166 Sep 16, 2026
Advantech EKI-1242IEIMS V1.06.01 Web UI Code Injection (CWE-94) Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.
CVE-2026-73165 Sep 16, 2026
Advantech EKI-1242IEIMS V1.06.01 OS Command Injection via Web UI Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
CVE-2026-73164 Sep 16, 2026
Advantech EKI-1242IEIMS v1.06.01 OS Command Injection via Web UI Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
CVE-2026-73163 Sep 16, 2026
Advantech EKI-1242IEIMS V1.06.01 OS Command Injection Root Access Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
CVE-2026-19535 Sep 16, 2026
CVE-2026-19535: CSRF in LuCI Admin UI of Advantech EKI-1242IEIMS Firmware 1.06.01 Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.
CVE-2026-79698 Sep 07, 2026
Advantech WISE-6610 Node-RED Lib Cmd Injection (pre-1.2.4) A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Wise 6610 Nb
Wise 6610 Eb
Wise 6610 Tb
And others...
CVE-2026-79697 Sep 07, 2026
Advantech WISE-6610 BasicStation Cert Delete Cmd Injection (<1.2.4) A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Wise 6610 Nb
Wise 6610 Eb
Wise 6610 Tb
And others...
CVE-2026-43833 Jul 31, 2026
Authn Stack Buffer Overflow in Upload (CVE-2026-43833) Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43832 Jul 31, 2026
Stack Buffer Overflow in Cookie Parsing with SafeEnhancement Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43831 Jul 31, 2026
Unauthenticated Stack BufOverflow in log msg enabling code exec Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43830 Jul 31, 2026
Firmware Upgrade File Verification Command Injection (CVE-2026-43830) Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43829 Jul 31, 2026
Unauthenticated Stack-Based Buffer Overflow in SafeEnhancement Password Feature Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-6890 Jul 31, 2026
Default root SSH creds in Advantech ECU-1251D IoT device
CVE-2026-6889 Jul 31, 2026
DNP3 Daemon DoS via Null File on Advantech ECU-1251D
CVE-2026-14162 Jun 30, 2026
Advantech Hospital Queuing Mgmt APIDoc Endpoint Exposes Sensitive Data Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
CVE-2026-14161 Jun 30, 2026
Advantech Hospital Quening Mgmt SDE via API Docs URL Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
CVE-2026-36226 May 22, 2026
CrossSite Scripting in Advantech WebAccess/SCADA 8.0-2015.08.16 via decryption field Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component
Webaccess Scada
CVE-2026-6888 May 13, 2026
Auth SQLi Exec Arbitrary Cmd via Interface Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.
Webaccessscada
Webaccess
CVE-2026-2670 Feb 18, 2026
OS Command Injection Advantech WISE-6610 1.2.1_20251110 openvpn_apply A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."
Wise 6610 Nb
Wise 6610 Eb
Wise 6610 Tb
And others...
CVE-2025-52694 Jan 12, 2026
SQLi Remote Exec in Unknown Web Service Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
CVE-2025-67653 Dec 18, 2025
Advantech WebAccess/SCADA Directory Traversal (CVE-2025-67653) Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.
Webaccessscada
Webaccess Scada
CVE-2025-46268 Dec 18, 2025
SQLi in Advantech WebAccess/SCADA Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.
Webaccessscada
CVE-2025-14848 Dec 18, 2025
Advantech WebAccess/SCADA Abs Dir Traversal Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
Webaccessscada
Webaccess
CVE-2025-14849 Dec 18, 2025
Advantech WebAccess SCADA Unrestricted File Upload Allowing Remote Code Exec Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
Webaccessscada
Webaccess Scada
CVE-2025-14850 Dec 18, 2025
Dir Traversal in Advantech WebAccess/SCADA Allows Arbitrary File Deletion Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
Webaccessscada
Webaccess Scada
CVE-2025-14252 Dec 16, 2025
Priv Esc in Advantech SUSI Driver 5.0.24335 via Improper Access An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior.
CVE-2025-34256 Dec 05, 2025
Advantech WISE-DeviceOn 5.4- HS512 HMAC Key Hard-coded JWT Forge Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOns remote management features.
Wise Deviceon Server
CVE-2025-34265 Dec 05, 2025
Stored XSS in Advantech WISE-DeviceOn Server rmm/v1/rule-engines (5.3) Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings or detail views without proper HTML sanitation. An attacker can inject malicious script into one or more of these fields, which is then executed in the browser context of users who view or interact with the affected rule, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34263 Dec 05, 2025
Advantech WISE-DeviceOn Server <5.4 XSS via /rmm/v1/plugin-config/dashboards/menus Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin configuration data and later rendered in the dashboard UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected dashboard, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34266 Dec 05, 2025
Advantech WISE-DeviceOn Server <5.4 XSS via /rmm/v1/plugin-config/addins/menus Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and later rendered in the AddIns UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected AddIns entry, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34264 Dec 05, 2025
Advantech WISE-DeviceOn Server <=5.4: XSS in Software Watchdog UI Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34262 Dec 05, 2025
Advantech WISE-DeviceOn <5.4 Stored XSS in /rmm/v1/devices/name/{agent_id} Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without proper HTML sanitation. An attacker can inject malicious script into the device name, which is then executed in the browser context of users who view or interact with the affected device, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34258 Dec 05, 2025
Advantech WISE-DeviceOn Server <5.4 XSS in /rmm/v1/devicemap/plan Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. An attacker can inject malicious script into the area name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34259 Dec 05, 2025
Advantech WISE-DeviceOn XSS in /devicemap/building (pre-5.4) Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without HTML sanitzation. An attacker can inject malicious script into the map entry name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34261 Dec 05, 2025
XSS in Advantech WISE-DeviceOn Server <5.4 via /rmm/v1/devicegroups/ Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected device group, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34260 Dec 05, 2025
Advantech WISE-DeviceOn Server <5.4 XSS via /rmm/v1/action/schedule Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sanitation. An attacker can inject malicious script into the schedule name, which is then executed in the browser context of users who view or interact with the affected schedule, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-34257 Dec 05, 2025
Advantech WISE-DeviceOn Server <=5.3 XSS via /rmm/v1/action/defined Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim.
Wise Deviceon Server
CVE-2025-13373 Dec 04, 2025
Advantech iView <=5.7.05.7057 SQL injection via SNMP v1 trap (Port 162) Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.
Iview
CVE-2025-58423 Nov 06, 2025
Insufficient Sanitization in File Upload Enables Path Traversal, File Access and DOS (CVE-2025-58423 Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.
Deviceon Iedge
CVE-2025-59171 Nov 06, 2025
RCE via Unsanitized Config File Upload and Directory Traversal Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
Deviceon Iedge
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.