← Back

Deviceon/iedge

deviceon/iedge

Vendor: Advantech • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system...Show more
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.Show less
1Advantech
1Deviceon/iedge
Jun 17, 2026
Jan 28, 2022
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker...Show more
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.Show less