OS Command Injection Advantech WISE-6610 1.2.1_20251110 openvpn_apply
CVE-2026-2670 Published on February 18, 2026

Advantech WISE-6610-NB Background Management openvpn_apply os command injection
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."

NVD

Timeline

Advisory disclosed

VulDB entry created

Countermeasure disclosed 196 days later.

VulDB entry last update 5 days later.

Weakness Types

What is a Shell injection Vulnerability?

The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CVE-2026-2670 has been classified to as a Shell injection vulnerability or weakness.

What is a Command Injection Vulnerability?

The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CVE-2026-2670 has been classified to as a Command Injection vulnerability or weakness.


Products Associated with CVE-2026-2670

Want to know whenever a new CVE is published for Advantech products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Advantech WISE-6610-NB: Advantech WISE-6610-EB: Advantech WISE-6610-TB: Advantech WISE-6610-JB: Advantech WISE-6610-CB: Advantech WISE-6610-EL-NB: Advantech WISE-6610-EL-EB: Advantech WISE-6610-EL-TB: Advantech WISE-6610-EL-JB: Advantech WISE-6610-EL-CB: Advantech WISE-6610P-DEA: Advantech WISE-6610P-DNA: Advantech WISE-6610P-DTA:

Exploit Probability

EPSS
16.30%
Percentile
96.62%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.