← Back

Advantech

advantech

378 CVEs • 95 products

Products (95)

Click to collapse
Toggle
Webaccess
webaccess
R Seenet
r-seenet
Iview
iview
Webaccess/nms
webaccess/nms
Webaccess/vpn
webaccess/vpn
Wise Paas/rmm
wise-paas/rmm
Susiaccess
susiaccess
Adam 6015
adam-6015
Adam 6017
adam-6017
Adam 6018
adam-6018
Adam 6022
adam-6022
Adam 6024
adam-6024
Adam 6050
adam-6050
Adam 6050w
adam-6050w
Adam 6051
adam-6051
Adam 6051w
adam-6051w
Adam 6052
adam-6052
Adam 6060
adam-6060
Adam 6060w
adam-6060w
Adam 6066
adam-6066
Adam 6501
adam-6501
Eki 6340
eki-6340
Adamview
adamview
Webop
webop
Diaganywhere
diaganywhere
Sq Manager
sq_manager
Wise Paas/ota
wise-paas/ota
Eki 1221
eki-1221
Eki 1221d
eki-1221d
Eki 1222
eki-1222
Eki 1222d
eki-1222d
Eki 1224
eki-1224
Eki 1321
eki-1321
Eki 1322
eki-1322
Eki 1361
eki-1361
Eki 1362
eki-1362
Vesp211 Eu
vesp211-eu
Vesp211 232
vesp211-232
Adam 3600
adam-3600
Eki 1521
eki-1521
Eki 1522
eki-1522
Eki 1524
eki-1524
Adam 5630
adam-5630
Adam 5550
adam-5550
Eki 6333ac 2g
eki-6333ac-2g
Wise 4060lan
wise-4060lan
Wise 4050lan
wise-4050lan
Wise 4010lan
wise-4010lan
Tp 3250
tp_3250

CVEs (378)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
5Iot Edge Linux Docker
Iot Edge WindowsIotsuite Growth Linux Docker+2 more
Jun 17, 2026
Jan 12, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affect...Show more
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
5.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
5.3 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
7.2 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
5.3 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu e...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and later rendered in the AddIns UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected AddIns entry, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings or detail views without proper HTML sanitation. An attacker can inject malicious script into one or more of these fields, which is then executed in the browser context of users who view or interact with the affected rule, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rul...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin configuration data and later rendered in the dashboard UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected dashboard, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name va...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without proper HTML sanitation. An attacker can inject malicious script into the device name, which is then executed in the browser context of users who view or interact with the affected device, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and descri...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected device group, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sanitation. An attacker can inject malicious script into the schedule name, which is then executed in the browser context of users who view or interact with the affected schedule, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name paramete...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without HTML sanitzation. An attacker can inject malicious script into the map entry name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name para...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. An attacker can inject malicious script into the area name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim.Show less
1Advantech
1Wise Deviceon Server
Jun 17, 2026
Dec 5, 2025
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server acce...Show more
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.Show less
1Advantech
1Tp 3250 Firmware
Jun 17, 2026
Nov 14, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output bu...Show more
A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size matches the input buffer size, leading to invalid memory operations and heap corruption. This vulnerability can cause denial of service through application crashes and potentially lead to code execution in user space. Local access is required to exploit this vulnerability.Show less
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.