OS Command Injection Advantech WISE-6610 1.2.1_20251110 openvpn_apply
CVE-2026-2670 Published on February 18, 2026
Advantech WISE-6610-NB Background Management openvpn_apply os command injection
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."
Timeline
Advisory disclosed
VulDB entry created
Countermeasure disclosed 196 days later.
VulDB entry last update 5 days later.
Weakness Types
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-2670 has been classified to as a Shell injection vulnerability or weakness.
What is a Command Injection Vulnerability?
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVE-2026-2670 has been classified to as a Command Injection vulnerability or weakness.
Products Associated with CVE-2026-2670
Want to know whenever a new CVE is published for Advantech products? stack.watch will email you.
Affected Versions
Advantech WISE-6610-NB:- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
- Version 1.2.1_20251110 is affected.
- Version 1.2.4_20260821 is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.