Search

Find a vulnerability

Search criteria

    161 vulnerabilities by Advantech

    CVE-2026-73177 (GCVE-0-2026-73177)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:03 – Updated: 2026-09-17 18:59
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:58 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73177",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:58:48.842501Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:59:04.930Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-185",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-185 Malicious Software Update"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "CWE-345 Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:03:44.204Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73177"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73177",
        "datePublished": "2026-09-16T13:03:44.204Z",
        "dateReserved": "2026-08-11T09:36:40.350Z",
        "dateUpdated": "2026-09-17T18:59:04.930Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73176 (GCVE-0-2026-73176)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:03 – Updated: 2026-09-17 18:58
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:58 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73176",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:58:21.678731Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:58:32.508Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:03:07.461Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73176"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73176",
        "datePublished": "2026-09-16T13:03:07.461Z",
        "dateReserved": "2026-08-11T09:36:40.350Z",
        "dateUpdated": "2026-09-17T18:58:32.508Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73175 (GCVE-0-2026-73175)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:02 – Updated: 2026-09-17 18:57
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:57 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73175",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:57:39.326685Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:57:57.089Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-469",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-469 HTTP DoS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:02:01.469Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73175"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73175",
        "datePublished": "2026-09-16T13:02:01.469Z",
        "dateReserved": "2026-08-11T09:36:40.350Z",
        "dateUpdated": "2026-09-17T18:57:57.089Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73174 (GCVE-0-2026-73174)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:59 – Updated: 2026-09-17 18:57
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:56 UTC
    CWE
    • CWE-319 - Cleartext Transmission of Sensitive Information
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73174",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:56:31.660338Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:57:11.067Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-118",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-118 Collect Data from Common Resource Locations"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "CWE-319 Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:59:58.416Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73174"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73174",
        "datePublished": "2026-09-16T12:59:58.416Z",
        "dateReserved": "2026-08-11T09:36:40.350Z",
        "dateUpdated": "2026-09-17T18:57:11.067Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73173 (GCVE-0-2026-73173)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:58 – Updated: 2026-09-17 18:56
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:56 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73173",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:56:03.810842Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:56:14.113Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:58:45.716Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73173"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73173",
        "datePublished": "2026-09-16T12:58:45.716Z",
        "dateReserved": "2026-08-11T09:36:40.350Z",
        "dateUpdated": "2026-09-17T18:56:14.113Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73172 (GCVE-0-2026-73172)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:57 – Updated: 2026-09-17 18:54
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:53 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73172",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:53:42.871050Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:54:00.909Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:57:44.107Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73172"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73172",
        "datePublished": "2026-09-16T12:57:44.107Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:54:00.909Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73171 (GCVE-0-2026-73171)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:55 – Updated: 2026-09-17 18:52
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:52 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73171",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:52:47.002580Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:52:54.931Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:55:10.609Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73171"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73171",
        "datePublished": "2026-09-16T12:55:10.609Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:52:54.931Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73170 (GCVE-0-2026-73170)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:53 – Updated: 2026-09-17 18:52
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:52 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73170",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:52:17.371888Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:52:30.289Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027) vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027) vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:53:50.284Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73170"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73170",
        "datePublished": "2026-09-16T12:53:50.284Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:52:30.289Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73169 (GCVE-0-2026-73169)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:52 – Updated: 2026-09-17 18:51
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:51 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73169",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:51:34.899608Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:51:45.518Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-63",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-63 Cross-Site Scripting"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:52:50.592Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73169"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73169",
        "datePublished": "2026-09-16T12:52:50.592Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:51:45.518Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73167 (GCVE-0-2026-73167)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:51 – Updated: 2026-09-17 18:51
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:51 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73167",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:51:03.314597Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:51:15.648Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:51:11.193Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73167"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73167",
        "datePublished": "2026-09-16T12:51:11.193Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:51:15.648Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73166 (GCVE-0-2026-73166)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:50 – Updated: 2026-09-17 19:11
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 19:10 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73166",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T19:10:55.820578Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T19:11:05.990Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:50:15.751Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73166"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73166",
        "datePublished": "2026-09-16T12:50:15.751Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T19:11:05.990Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73165 (GCVE-0-2026-73165)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:44 – Updated: 2026-09-17 18:49
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:49 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73165",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:49:08.390546Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:49:23.380Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:44:32.620Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73165"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73165",
        "datePublished": "2026-09-16T12:44:32.620Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:49:23.380Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73164 (GCVE-0-2026-73164)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:37 – Updated: 2026-09-17 18:48
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:48 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73164",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:48:39.526591Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:48:53.645Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:37:25.212Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73164"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73164",
        "datePublished": "2026-09-16T12:37:25.212Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:48:53.645Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-73163 (GCVE-0-2026-73163)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:36 – Updated: 2026-09-17 18:48
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:48 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-73163",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:48:06.130519Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:48:24.768Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:36:36.769Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-73163"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-73163",
        "datePublished": "2026-09-16T12:36:36.769Z",
        "dateReserved": "2026-08-11T09:36:13.097Z",
        "dateUpdated": "2026-09-17T18:48:24.768Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-19535 (GCVE-0-2026-19535)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:35 – Updated: 2026-09-17 18:47
    VLAI
    Summary
    Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 18:47 UTC
    CWE
    • CWE-352 - Cross-Site Request Forgery (CSRF)
    References
    Impacted products
    Vendor Product Version
    Advantech EKI-1242IEIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Advantech EKI-1242EIMS Affected: 0 , ≤ 1.06.01 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-19535",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T18:47:19.924762Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T18:47:44.061Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242IEIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EKI-1242EIMS",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "1.06.01",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Simone Bossi at Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eNozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.\u003c/p\u003e"
                }
              ],
              "value": "Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-62",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-62 Cross Site Request Forgery"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-352",
                  "description": "CWE-352 Cross-Site Request Forgery (CSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:35:36.304Z",
            "orgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
            "shortName": "Nozomi"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-19535"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://advcloudfiles.advantech.com/cms/5dafee28-ad53-4d07-a328-7896fcc24b6e/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bec8025f-a851-46e5-b3a3-058e6b0aa23c",
        "assignerShortName": "Nozomi",
        "cveId": "CVE-2026-19535",
        "datePublished": "2026-09-16T12:35:36.304Z",
        "dateReserved": "2026-08-11T09:36:52.957Z",
        "dateUpdated": "2026-09-17T18:47:44.061Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79698 (GCVE-0-2026-79698)

    Vulnerability from cvelistv5 – Published: 2026-09-07 06:30 – Updated: 2026-09-11 20:35
    VLAI
    Title
    Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
    Summary
    A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 20:15 UTC
    CWE
    Impacted products
    Vendor Product Version
    Advantech WISE-6610-NB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-TB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-JB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-CB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-NB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-EB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-TB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-JB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-CB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DEA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DNA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DTA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79698",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T20:15:46.440772Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T20:35:36.242Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-NB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-EB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-TB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-JB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-CB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-EL-NB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-EL-EB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-EL-TB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-EL-JB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610-EL-CB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610P-DEA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610P-DNA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Node-RED Library"
              ],
              "product": "WISE-6610P-DTA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "hubdk01 (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 9,
                "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T06:30:41.668Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-399513 | Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/399513"
            },
            {
              "name": "VDB-399513 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/399513/cti"
            },
            {
              "name": "CVE-2026-79698 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-79698"
            },
            {
              "name": "Submit #879219 | Advantech Technology (China) Co., Ltd. WISE-6610 v1.2.1_20251110 Command Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/879219"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://uvxbywu62qm.feishu.cn/wiki/RgziwoXf2iD9zKkI4MJcfWcNn7c?from=from_copylink"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://www.advantech.com/zh-tw/security-advisory"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.advantech.com/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-02T00:00:00.000Z",
              "value": "Countermeasure disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-07T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-07T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-07T08:03:06.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-79698",
        "datePublished": "2026-09-07T06:30:41.668Z",
        "dateReserved": "2026-08-25T12:13:42.095Z",
        "dateUpdated": "2026-09-11T20:35:36.242Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79697 (GCVE-0-2026-79697)

    Vulnerability from cvelistv5 – Published: 2026-09-07 06:15 – Updated: 2026-09-08 13:42
    VLAI
    Title
    Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
    Summary
    A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 13:42 UTC
    CWE
    Impacted products
    Vendor Product Version
    Advantech WISE-6610-NB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-TB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-JB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-CB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-NB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-EB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-TB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-JB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-CB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DEA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DNA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DTA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79697",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T13:42:20.317863Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T13:42:30.075Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-NB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-EB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-TB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-JB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-CB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-EL-NB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-EL-EB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-EL-TB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-EL-JB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610-EL-CB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610P-DEA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610P-DNA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Basic Station Certificate-Deletion Handler"
              ],
              "product": "WISE-6610P-DTA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "hubdk01 (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 9,
                "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T06:15:42.278Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-399512 | Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/399512"
            },
            {
              "name": "VDB-399512 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/399512/cti"
            },
            {
              "name": "CVE-2026-79697 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-79697"
            },
            {
              "name": "Submit #879208 | Advantech Technology (China) Co., Ltd. WISE-6610 v1.2.1_20251110 Command Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/879208"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://uvxbywu62qm.feishu.cn/wiki/EzwXwS0vKiroHmk9rqzcjP0EnMe?from=from_copylink"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://www.advantech.com/zh-tw/security-advisory"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.advantech.com/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-02T00:00:00.000Z",
              "value": "Countermeasure disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-07T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-07T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-07T08:02:57.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-79697",
        "datePublished": "2026-09-07T06:15:42.278Z",
        "dateReserved": "2026-08-25T12:13:37.537Z",
        "dateUpdated": "2026-09-08T13:42:30.075Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-14162 (GCVE-0-2026-14162)

    Vulnerability from cvelistv5 – Published: 2026-06-30 10:57 – Updated: 2026-06-30 12:25
    VLAI
    Title
    Advantech|Hospital Quering Management - Missing Authentication
    Summary
    Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-30 12:25 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    References
    Impacted products
    Vendor Product Version
    Advantech Hospital Quering Management Affected: 0 , < 1.2.13 (custom)
    Create a notification for this product.
    Date Public
    2026-06-30 10:54
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-14162",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-30T12:25:02.527865Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-30T12:25:08.646Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Hospital Quering Management",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThan": "1.2.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2026-06-30T10:54:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation."
                }
              ],
              "value": "Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-30T10:57:11.421Z",
            "orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
            "shortName": "twcert"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.twcert.org.tw/tw/cp-132-11011-999eb-1.html"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.twcert.org.tw/en/cp-139-11012-63761-2.html"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update HQM ISO to version 1.2.13 or later, or update QueueHttp.dll to version 1.2.12.7 or later."
                }
              ],
              "value": "Update HQM ISO to version 1.2.13 or later, or update QueueHttp.dll to version 1.2.12.7 or later."
            }
          ],
          "source": {
            "advisory": "TVN-202606007",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech\uff5cHospital Quering Management - Missing Authentication",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
        "assignerShortName": "twcert",
        "cveId": "CVE-2026-14162",
        "datePublished": "2026-06-30T10:57:11.421Z",
        "dateReserved": "2026-06-30T02:02:24.547Z",
        "dateUpdated": "2026-06-30T12:25:08.646Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-14161 (GCVE-0-2026-14161)

    Vulnerability from cvelistv5 – Published: 2026-06-30 10:52 – Updated: 2026-06-30 12:26
    VLAI
    Title
    Advantech|Hospital Queuing Management - Sensitive Data Exposure
    Summary
    Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-30 12:26 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    References
    Impacted products
    Vendor Product Version
    Advantech Hospital Queuing Management Affected: 0 , < 1.2.13 (custom)
    Create a notification for this product.
    Date Public
    2026-06-30 08:10
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-14161",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-30T12:26:24.427457Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-30T12:26:28.971Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Hospital Queuing Management",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThan": "1.2.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2026-06-30T08:10:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u0026nbsp;Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation."
                }
              ],
              "value": "Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-30T10:52:38.293Z",
            "orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
            "shortName": "twcert"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.twcert.org.tw/tw/cp-132-11011-999eb-1.html"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.twcert.org.tw/en/cp-139-11012-63761-2.html"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update HQM ISO to version 1.2.13 or later, or update QueueHttp.dll to version 1.2.12.7 or later."
                }
              ],
              "value": "Update HQM ISO to version 1.2.13 or later, or update QueueHttp.dll to version 1.2.12.7 or later."
            }
          ],
          "source": {
            "advisory": "TVN-202606007",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech\uff5cHospital Queuing Management - Sensitive Data Exposure",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
        "assignerShortName": "twcert",
        "cveId": "CVE-2026-14161",
        "datePublished": "2026-06-30T10:52:38.293Z",
        "dateReserved": "2026-06-30T02:02:22.471Z",
        "dateUpdated": "2026-06-30T12:26:28.971Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-6888 (GCVE-0-2026-6888)

    Vulnerability from cvelistv5 – Published: 2026-05-13 03:16 – Updated: 2026-05-13 14:35
    VLAI
    Title
    SQL Injection Vulnerability
    Summary
    Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-13 14:35 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Assigner
    Date Public
    2026-05-13 02:54
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-6888",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-13T14:35:40.247452Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-13T14:35:53.880Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "SaaS Composer",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 3.4.17"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "IoTSuite Growth Linux docker",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 2.2.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "IoTSuite Starter Linux docker",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 2.2.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "IoT Edge Linux docker",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 2.2.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "IoT Edge Windows",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 2.2.0"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WebAccess/SCADA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 9.2.3"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WebAccess SaaS-Composer",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 3.4.17.1"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "ECOWatch SaaS-Composer",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to version 3.4.17"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Hoa Ly Van Huu"
            }
          ],
          "datePublic": "2026-05-13T02:54:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eSuccessful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to\nexecute arbitrary commands via a specific interface,\npotentially enabling the attacker to access, modify, or delete sensitive\ninformation within the database.\u003c/p\u003e"
                }
              ],
              "value": "Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to\nexecute arbitrary commands via a specific interface,\npotentially enabling the attacker to access, modify, or delete sensitive\ninformation within the database."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-13T03:16:24.701Z",
            "orgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
            "shortName": "CSA"
          },
          "references": [
            {
              "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-050/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eUsers and administrators of\naffected product versions are advised to update to the latest versions\nimmediately.\u003c/p\u003e\n\n\u003cp\u003eFor SaaS Composer, IoTSuite Growth\nLinux docker, IoT Edge Windows, and ECOWatch please contact Advantech\u0026nbsp;\u003ca href=\"https://wise-iot.advantech.com/en-tw/marketplace/help/technical-support\"\u003ehere\u0026nbsp;\u003c/a\u003efor\nthe official release of the fixed version.\u003c/p\u003e\n\n\u003cp\u003eFor IoTSuite Starter Linux docker,\nplease refer to the update guide\u0026nbsp;\u003ca href=\"https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq?tenantId=VGVuYW50.aSUET6-KO-0qXOBh\"\u003ehere\u003c/a\u003e.\nAs the update involves a reinstallation process, please refer to the\nreinstallation guide \u003ca href=\"https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/JqNWAMGz1JQ?tenantId=VGVuYW50.aSUET6-KO-0qXOBh\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eFor IoT Edge Linux docker, please\nrefer to the update guide\u0026nbsp;\u003ca href=\"https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq?tenantId=VGVuYW50.aSUET6-KO-0qXOBh\"\u003ehere\u003c/a\u003e.\nAs the update involves a reinstallation process, please refer to the\nreinstallation guide \u003ca href=\"https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/G0yWBn2mp2q?tenantId=VGVuYW50.aSUET6-KO-0qXOBh\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eFor WebAccess/SCADA and WebAccess\nSaaS-Composer, please refer to the update guide \u003ca href=\"https://www.advantech.com/en/support/details/installation?id=1-MS9MJV\"\u003ehere\u003c/a\u003e.\u003c/p\u003e"
                }
              ],
              "value": "Users and administrators of\naffected product versions are advised to update to the latest versions\nimmediately.\n\n\n\n\n\nFor SaaS Composer, IoTSuite Growth\nLinux docker, IoT Edge Windows, and ECOWatch please contact Advantech\u00a0 here\u00a0 https://wise-iot.advantech.com/en-tw/marketplace/help/technical-support for\nthe official release of the fixed version.\n\n\n\n\n\nFor IoTSuite Starter Linux docker,\nplease refer to the update guide\u00a0 here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq .\nAs the update involves a reinstallation process, please refer to the\nreinstallation guide  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/JqNWAMGz1JQ .\n\n\n\n\n\nFor IoT Edge Linux docker, please\nrefer to the update guide\u00a0 here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq .\nAs the update involves a reinstallation process, please refer to the\nreinstallation guide  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/G0yWBn2mp2q .\n\n\n\n\n\nFor WebAccess/SCADA and WebAccess\nSaaS-Composer, please refer to the update guide  here https://www.advantech.com/en/support/details/installation ."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "SQL Injection Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "assignerShortName": "CSA",
        "cveId": "CVE-2026-6888",
        "datePublished": "2026-05-13T03:16:24.701Z",
        "dateReserved": "2026-04-23T02:58:12.750Z",
        "dateUpdated": "2026-05-13T14:35:53.880Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-2670 (GCVE-0-2026-2670)

    Vulnerability from cvelistv5 – Published: 2026-02-18 21:02 – Updated: 2026-09-07 05:58
    VLAI
    Title
    Advantech WISE-6610-NB Background Management openvpn_apply os command injection
    Summary
    A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-20 19:32 UTC
    CWE
    Impacted products
    Vendor Product Version
    Advantech WISE-6610-NB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-TB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-JB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-CB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-NB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-EB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-TB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-JB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610-EL-CB Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DEA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DNA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Advantech WISE-6610P-DTA Affected: 1.2.1_20251110
    Unaffected: 1.2.4_20260821
        cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-2670",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-20T19:32:36.994708Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-20T19:32:51.761Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-NB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-EB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-TB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-JB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-CB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-EL-NB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-EL-EB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-EL-TB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-EL-JB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610-EL-CB",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610P-DEA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610P-DNA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Background Management"
              ],
              "product": "WISE-6610P-DTA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.1_20251110"
                },
                {
                  "status": "unaffected",
                  "version": "1.2.4_20260821"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "jiefengliang (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: \"The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data.\""
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 8.3,
                "vectorString": "AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T05:58:16.410Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-346467 | Advantech WISE-6610-NB Background Management openvpn_apply os command injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/346467"
            },
            {
              "name": "VDB-346467 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/346467/cti"
            },
            {
              "name": "CVE-2026-2670 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-2670"
            },
            {
              "name": "Submit #753293 | Advantech WISE-6610 v1.2.1_20251110 OS Command Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/753293"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/master-abc/cve/issues/37"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://www.advantech.com/zh-tw/security-advisory"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.advantech.com/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-02-18T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-02-18T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-02T00:00:00.000Z",
              "value": "Countermeasure disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-07T08:02:45.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Advantech WISE-6610-NB Background Management openvpn_apply os command injection",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-2670",
        "datePublished": "2026-02-18T21:02:08.426Z",
        "dateReserved": "2026-02-18T09:16:43.848Z",
        "dateUpdated": "2026-09-07T05:58:16.410Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-52694 (GCVE-0-2025-52694)

    Vulnerability from cvelistv5 – Published: 2026-01-12 02:27 – Updated: 2026-01-26 02:50
    VLAI
    Title
    Execution of arbitrary SQL commands
    Summary
    Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-12 14:31 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Assigner
    Impacted products
    Vendor Product Version
    Advantech IoTSuite and IoT Edge Products Affected: SaaSComposer prior to version V3.4.15
    Affected: IoTSuite Growth Linux docker prior to version V2.0.2
    Affected: IoTSuite Starter Linux docker prior to version V2.0.2
    Affected: IoT Edge Linux docker prior to version V2.0.2
    Affected: IoT Edge Windows prior to version V2.0.2
    Affected: WebAccess/SCADA prior to version V9.2.2
    Affected: WebAccess SaaS-Composer prior to version 3.4.15.1
    Affected: ECOWatch SaaS-Composer prior to version 3.4.15
    Create a notification for this product.
    Date Public
    2026-01-12 02:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-52694",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-12T14:31:37.398331Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-12T14:31:52.735Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "IoTSuite and IoT Edge Products",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "SaaSComposer prior to version V3.4.15"
                },
                {
                  "status": "affected",
                  "version": "IoTSuite Growth Linux docker prior to version V2.0.2"
                },
                {
                  "status": "affected",
                  "version": "IoTSuite Starter Linux docker prior to version V2.0.2"
                },
                {
                  "status": "affected",
                  "version": "IoT Edge Linux docker prior to version V2.0.2"
                },
                {
                  "status": "affected",
                  "version": "IoT Edge Windows prior to version V2.0.2"
                },
                {
                  "status": "affected",
                  "version": "WebAccess/SCADA prior to version V9.2.2"
                },
                {
                  "status": "affected",
                  "version": "WebAccess SaaS-Composer prior to version 3.4.15.1"
                },
                {
                  "status": "affected",
                  "version": "ECOWatch SaaS-Composer prior to version 3.4.15"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Loi Nguyen Thang"
            }
          ],
          "datePublic": "2026-01-12T02:21:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately."
                }
              ],
              "value": "Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-26T02:50:33.837Z",
            "orgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
            "shortName": "CSA"
          },
          "references": [
            {
              "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/alerts-al-2026-001/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\n\n\u003c/p\u003e\u003cdiv\u003eUsers and administrators of affected product versions are advised to update to the latest versions immediately.\u003c/div\u003e\u003cdiv\u003eFor IoTSuite SaaSComposer, IoTSuite Growth Linux docker, and IoT Edge Windows please contact Advantech \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://wise-iot.advantech.com/en-tw/marketplace/help/technical-support\"\u003ehere \u003c/a\u003efor the official release of the fixed version.\u003c/div\u003e\u003cdiv\u003eFor IoTSuite Starter Linux docker, please download the update \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/JqNWAMGz1JQ?tenantId=VGVuYW50.aSUET6-KO-0qXOBh\"\u003ehere\u003c/a\u003e.\u003c/div\u003e\u003cdiv\u003eFor IoT Edge Linux docker, please download the update \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/G0yWBn2mp2q?tenantId=VGVuYW50.aSUET6-KO-0qXOBh\"\u003ehere\u003c/a\u003e.\u003c/div\u003e\n\n\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "Users and administrators of affected product versions are advised to update to the latest versions immediately.\n\nFor IoTSuite SaaSComposer, IoTSuite Growth Linux docker, and IoT Edge Windows please contact Advantech  here  https://wise-iot.advantech.com/en-tw/marketplace/help/technical-support for the official release of the fixed version.\n\nFor IoTSuite Starter Linux docker, please download the update  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/JqNWAMGz1JQ .\n\nFor IoT Edge Linux docker, please download the update  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/G0yWBn2mp2q ."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Execution of arbitrary SQL commands",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "assignerShortName": "CSA",
        "cveId": "CVE-2025-52694",
        "datePublished": "2026-01-12T02:27:16.744Z",
        "dateReserved": "2025-06-19T06:04:41.987Z",
        "dateUpdated": "2026-01-26T02:50:33.837Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-67653 (GCVE-0-2025-67653)

    Vulnerability from cvelistv5 – Published: 2025-12-18 20:38 – Updated: 2025-12-18 21:46
    VLAI
    Title
    Advantech WebAccess/SCADA Path Traversal
    Summary
    Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 21:01 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-67653",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T21:01:07.058903Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-18T21:46:25.952Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WebAccess/SCADA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.2.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech WebAccess/SCADA\u0026nbsp;is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files."
                }
              ],
              "value": "Advantech WebAccess/SCADA\u00a0is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-18T20:38:12.958Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-06"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-06.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech recommends users apply the following mitigations and update to \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV\"\u003eWebAccess/SCADA: Version 9.2.2\u003c/a\u003e.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Advantech recommends users apply the following mitigations and update to  WebAccess/SCADA: Version 9.2.2 https://www.advantech.com/en-us/support/details/installation ."
            }
          ],
          "source": {
            "advisory": "ICSA-25-352-06",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech WebAccess/SCADA Path Traversal",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2025-67653",
        "datePublished": "2025-12-18T20:38:12.958Z",
        "dateReserved": "2025-12-09T20:16:53.210Z",
        "dateUpdated": "2025-12-18T21:46:25.952Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-46268 (GCVE-0-2025-46268)

    Vulnerability from cvelistv5 – Published: 2025-12-18 20:35 – Updated: 2025-12-18 21:46
    VLAI
    Title
    Advantech WebAccess/SCADA SQL Injection
    Summary
    Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 21:01 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-46268",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T21:01:36.611654Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-18T21:46:32.063Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WebAccess/SCADA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.2.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech WebAccess/SCADA\u0026nbsp;\nis vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands."
                }
              ],
              "value": "Advantech WebAccess/SCADA\u00a0\nis vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-18T20:36:44.775Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-06"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-06.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech recommends users apply the following mitigations and update to \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV\"\u003eWebAccess/SCADA: Version 9.2.2\u003c/a\u003e.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Advantech recommends users apply the following mitigations and update to  WebAccess/SCADA: Version 9.2.2 https://www.advantech.com/en-us/support/details/installation ."
            }
          ],
          "source": {
            "advisory": "ICSA-25-352-06",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech WebAccess/SCADA SQL Injection",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2025-46268",
        "datePublished": "2025-12-18T20:35:36.866Z",
        "dateReserved": "2025-07-30T19:03:10.153Z",
        "dateUpdated": "2025-12-18T21:46:32.063Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-14848 (GCVE-0-2025-14848)

    Vulnerability from cvelistv5 – Published: 2025-12-18 20:34 – Updated: 2025-12-18 21:46
    VLAI
    Title
    Advantech WebAccess/SCADA Absolute Path Traversal
    Summary
    Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 21:01 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-14848",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T21:01:58.179423Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-18T21:46:40.178Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WebAccess/SCADA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.2.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech WebAccess/SCADA\nis vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files."
                }
              ],
              "value": "Advantech WebAccess/SCADA\nis vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-36",
                  "description": "CWE-36",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-18T20:34:03.497Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-06"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-06.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech recommends users apply the following mitigations and update to \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV\"\u003eWebAccess/SCADA: Version 9.2.2\u003c/a\u003e.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Advantech recommends users apply the following mitigations and update to  WebAccess/SCADA: Version 9.2.2 https://www.advantech.com/en-us/support/details/installation ."
            }
          ],
          "source": {
            "advisory": "ICSA-25-352-06",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech WebAccess/SCADA Absolute Path Traversal",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2025-14848",
        "datePublished": "2025-12-18T20:34:03.497Z",
        "dateReserved": "2025-12-17T18:57:55.208Z",
        "dateUpdated": "2025-12-18T21:46:40.178Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-14849 (GCVE-0-2025-14849)

    Vulnerability from cvelistv5 – Published: 2025-12-18 20:32 – Updated: 2025-12-18 21:46
    VLAI
    Title
    Advantech WebAccess/SCADA Unrestricted Upload of File with Dangerous Type
    Summary
    Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 21:02 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-14849",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T21:02:39.843427Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-18T21:46:46.491Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WebAccess/SCADA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.2.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech WebAccess/SCADA\u0026nbsp;\nis vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code."
                }
              ],
              "value": "Advantech WebAccess/SCADA\u00a0\nis vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-18T20:32:38.746Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-06"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-06.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech recommends users apply the following mitigations and update to \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV\"\u003eWebAccess/SCADA: Version 9.2.2\u003c/a\u003e.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Advantech recommends users apply the following mitigations and update to  WebAccess/SCADA: Version 9.2.2 https://www.advantech.com/en-us/support/details/installation ."
            }
          ],
          "source": {
            "advisory": "ICSA-25-352-06",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech WebAccess/SCADA Unrestricted Upload of File with Dangerous Type",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2025-14849",
        "datePublished": "2025-12-18T20:32:38.746Z",
        "dateReserved": "2025-12-17T18:58:28.259Z",
        "dateUpdated": "2025-12-18T21:46:46.491Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-14850 (GCVE-0-2025-14850)

    Vulnerability from cvelistv5 – Published: 2025-12-18 20:30 – Updated: 2025-12-18 21:46
    VLAI
    Title
    Advantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted Directory
    Summary
    Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 21:03 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-14850",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T21:03:11.658719Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-18T21:46:52.446Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WebAccess/SCADA",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.2.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech WebAccess/SCADA\u0026nbsp;is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files."
                }
              ],
              "value": "Advantech WebAccess/SCADA\u00a0is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-18T20:30:56.575Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-06"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-06.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech recommends users apply the following mitigations and update to \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.advantech.com/en-us/support/details/installation?id=1-MS9MJV\"\u003eWebAccess/SCADA: Version 9.2.2\u003c/a\u003e.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Advantech recommends users apply the following mitigations and update to  WebAccess/SCADA: Version 9.2.2 https://www.advantech.com/en-us/support/details/installation ."
            }
          ],
          "source": {
            "advisory": "ICSA-25-352-06",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted Directory",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2025-14850",
        "datePublished": "2025-12-18T20:30:56.575Z",
        "dateReserved": "2025-12-17T18:59:18.176Z",
        "dateUpdated": "2025-12-18T21:46:52.446Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-14252 (GCVE-0-2025-14252)

    Vulnerability from cvelistv5 – Published: 2025-12-16 05:19 – Updated: 2026-01-07 15:06
    VLAI
    Summary
    An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-16 18:50 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    Advantech SUSI Affected: 0 , ≤ 5.0.24335 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-14252",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-16T18:50:59.298281Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-269",
                    "description": "CWE-269 Improper Privilege Management",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-07T15:06:49.701Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SUSI",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.24335",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior."
                }
              ],
              "value": "An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-16T05:19:54.675Z",
            "orgId": "3ad20294-822c-4ebc-9301-f9a7cf62d46e",
            "shortName": "TXOne"
          },
          "references": [
            {
              "url": "https://www.txone.com/psirt/advisories/CVE-2025-14252"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3ad20294-822c-4ebc-9301-f9a7cf62d46e",
        "assignerShortName": "TXOne",
        "cveId": "CVE-2025-14252",
        "datePublished": "2025-12-16T05:19:54.675Z",
        "dateReserved": "2025-12-08T06:58:53.661Z",
        "dateUpdated": "2026-01-07T15:06:49.701Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-13373 (GCVE-0-2025-13373)

    Vulnerability from cvelistv5 – Published: 2025-12-04 22:50 – Updated: 2025-12-05 14:41
    VLAI
    Title
    Advantech iView SQL Injection
    Summary
    Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-05 14:41 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    Advantech iView Affected: 5.7.05.7057
    Unaffected: 5.8.1
    Create a notification for this product.
    Date Public
    2025-12-04 17:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-13373",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-05T14:41:06.639585Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-05T14:41:15.442Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "iView",
              "vendor": "Advantech",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.7.05.7057"
                },
                {
                  "status": "unaffected",
                  "version": "5.8.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "m00nback reported this vulnerability to CISA."
            }
          ],
          "datePublic": "2025-12-04T17:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAdvantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.\u003c/span\u003e"
                }
              ],
              "value": "Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-04T22:50:36.079Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.advantech.com/zh-tw/support/details/firmware?id=1-HIPU-183"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-338-07"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-338-07.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAdvantech recommends users update to \u003c/span\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.advantech.com/zh-tw/support/details/firmware?id=1-HIPU-183\"\u003eiView v5.8.1\u003c/a\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e.\u003c/span\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "Advantech recommends users update to  iView v5.8.1 https://www.advantech.com/zh-tw/support/details/firmware ."
            }
          ],
          "source": {
            "advisory": "ICSA-25-338-07",
            "discovery": "EXTERNAL"
          },
          "title": "Advantech iView SQL Injection",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2025-13373",
        "datePublished": "2025-12-04T22:50:36.079Z",
        "dateReserved": "2025-11-18T18:48:07.936Z",
        "dateUpdated": "2025-12-05T14:41:15.442Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-58423 (GCVE-0-2025-58423)

    Vulnerability from cvelistv5 – Published: 2025-11-06 22:31 – Updated: 2025-12-01 15:36 Unsupported When Assigned
    VLAI
    Title
    Advantech DeviceOn/iEdge Path Traversal
    Summary
    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-11-07 18:01 UTC
    CWE
    Impacted products
    Vendor Product Version
    Advantech DeviceOn/iEdge Affected: 0 , ≤ 2.0.2 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-58423",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-11-07T18:01:11.831972Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-01T15:36:29.593Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "DeviceOn/iEdge",
              "vendor": "Advantech",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Williams of Pellera Technologies reported this vulnerability to CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Due to insufficient sanitization, an attacker can upload a specially \ncrafted configuration file to cause a denial-of-service condition, \ntraverse directories, or read/write files, within the context of the \nlocal system account."
                }
              ],
              "value": "Due to insufficient sanitization, an attacker can upload a specially \ncrafted configuration file to cause a denial-of-service condition, \ntraverse directories, or read/write files, within the context of the \nlocal system account."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-06T22:31:02.740Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-310-01"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-310-01.json"
            },
            {
              "url": "https://www.advantech.com/emt/contact"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Advantech has stated that the listed products are end-of-life, and \nrecommends all users upgrade their devices to DeviceOn, which is not \nvulnerable to these vulnerabilities. For further questions or upgrade \nassistance, users should \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.advantech.com/emt/contact\"\u003econtact Advantech\u003c/a\u003e.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Advantech has stated that the listed products are end-of-life, and \nrecommends all users upgrade their devices to DeviceOn, which is not \nvulnerable to these vulnerabilities. For further questions or upgrade \nassistance, users should  contact Advantech https://www.advantech.com/emt/contact ."
            }
          ],
          "source": {
            "advisory": "ICSA-25-310-01",
            "discovery": "EXTERNAL"
          },
          "tags": [
            "unsupported-when-assigned"
          ],
          "title": "Advantech DeviceOn/iEdge Path Traversal",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2025-58423",
        "datePublished": "2025-11-06T22:31:02.740Z",
        "dateReserved": "2025-11-05T16:45:22.604Z",
        "dateUpdated": "2025-12-01T15:36:29.593Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }