← Back

Advantech

advantech

378 CVEs • 95 products

Products (95)

Click to collapse
Toggle
Webaccess
webaccess
R Seenet
r-seenet
Iview
iview
Webaccess/nms
webaccess/nms
Webaccess/vpn
webaccess/vpn
Wise Paas/rmm
wise-paas/rmm
Susiaccess
susiaccess
Adam 6015
adam-6015
Adam 6017
adam-6017
Adam 6018
adam-6018
Adam 6022
adam-6022
Adam 6024
adam-6024
Adam 6050
adam-6050
Adam 6050w
adam-6050w
Adam 6051
adam-6051
Adam 6051w
adam-6051w
Adam 6052
adam-6052
Adam 6060
adam-6060
Adam 6060w
adam-6060w
Adam 6066
adam-6066
Adam 6501
adam-6501
Eki 6340
eki-6340
Adamview
adamview
Webop
webop
Diaganywhere
diaganywhere
Sq Manager
sq_manager
Wise Paas/ota
wise-paas/ota
Eki 1221
eki-1221
Eki 1221d
eki-1221d
Eki 1222
eki-1222
Eki 1222d
eki-1222d
Eki 1224
eki-1224
Eki 1321
eki-1321
Eki 1322
eki-1322
Eki 1361
eki-1361
Eki 1362
eki-1362
Vesp211 Eu
vesp211-eu
Vesp211 232
vesp211-232
Adam 3600
adam-3600
Eki 1521
eki-1521
Eki 1522
eki-1522
Eki 1524
eki-1524
Adam 5630
adam-5630
Adam 5550
adam-5550
Eki 6333ac 2g
eki-6333ac-2g
Wise 4060lan
wise-4060lan
Wise 4050lan
wise-4050lan
Wise 4010lan
wise-4010lan
Tp 3250
tp_3250

CVEs (378)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
1Advantech
1Deviceon/iedge
Jun 17, 2026
Nov 6, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system...Show more
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
5.1 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable sear...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatab...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatab...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datata...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
8.6 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search par...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable searc...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
8.6 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable se...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as t...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to ca...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web user (www-data) can access.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
6.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-sup...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.Show less
1Advantech
1Webaccess/vpn
Jun 17, 2026
Nov 6, 2025
6.2 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an...Show more
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.Show less
1Advantech
1Iview
Jun 17, 2026
Nov 6, 2025
9.3 CRITICAL· v4
7.2 HIGH· v3
N/A· v2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within...Show more
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.Show less
1Advantech
1Iview
Jun 17, 2026
Nov 6, 2025
8.8 HIGH· v4
7.5 HIGH· v3
N/A· v2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within...Show more
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.Show less
1Advantech
1Iview
Jun 17, 2026
Nov 6, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within...Show more
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.Show less
1Advantech
1Iview
Jun 17, 2026
Nov 6, 2025
9.3 CRITICAL· v4
7.2 HIGH· v3
N/A· v2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within...Show more
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.Show less
1Advantech
1Iview
Jun 17, 2026
Nov 6, 2025
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within...Show more
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.Show less
1Advantech
1Iview
Jun 17, 2026
Jul 11, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthoriz...Show more
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.Show less