← Back

Advantech

advantech

378 CVEs • 95 products

Products (95)

Click to collapse
Toggle
Webaccess
webaccess
R Seenet
r-seenet
Iview
iview
Webaccess/nms
webaccess/nms
Webaccess/vpn
webaccess/vpn
Wise Paas/rmm
wise-paas/rmm
Susiaccess
susiaccess
Adam 6015
adam-6015
Adam 6017
adam-6017
Adam 6018
adam-6018
Adam 6022
adam-6022
Adam 6024
adam-6024
Adam 6050
adam-6050
Adam 6050w
adam-6050w
Adam 6051
adam-6051
Adam 6051w
adam-6051w
Adam 6052
adam-6052
Adam 6060
adam-6060
Adam 6060w
adam-6060w
Adam 6066
adam-6066
Adam 6501
adam-6501
Eki 6340
eki-6340
Adamview
adamview
Webop
webop
Diaganywhere
diaganywhere
Sq Manager
sq_manager
Wise Paas/ota
wise-paas/ota
Eki 1221
eki-1221
Eki 1221d
eki-1221d
Eki 1222
eki-1222
Eki 1222d
eki-1222d
Eki 1224
eki-1224
Eki 1321
eki-1321
Eki 1322
eki-1322
Eki 1361
eki-1361
Eki 1362
eki-1362
Vesp211 Eu
vesp211-eu
Vesp211 232
vesp211-232
Adam 3600
adam-3600
Eki 1521
eki-1521
Eki 1522
eki-1522
Eki 1524
eki-1524
Adam 5630
adam-5630
Adam 5550
adam-5550
Eki 6333ac 2g
eki-6333ac-2g
Wise 4060lan
wise-4060lan
Wise 4050lan
wise-4050lan
Wise 4010lan
wise-4010lan
Tp 3250
tp_3250

CVEs (378)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "restore_config_from_utility" operation.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "backup_config_to_utility" operation.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "wlan_scan" operation.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "cfg_cmd_set_eth_conf" operation.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "multiple_ssid_htm" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "basic_htm" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "applications_apply" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "lan_apply" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "export_log" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "mp_apply" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "connection_profile_apply" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "certificate_file_remove" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "snmp_apply" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<=...Show more
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "scan_ap" API which are not properly sanitized before being concatenated to OS level commands.Show less
1Advantech
3Eki 6333ac 1gpo Firmware
Eki 6333ac 2g FirmwareEki 6333ac 2gd Firmware
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1...Show more
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.Show less
1Advantech
1Iview
Jun 17, 2026
Nov 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authenti...Show more
Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863.Show less
1Advantech
1Adam 5630 Firmware
Jun 17, 2026
Sep 27, 2024
8.5 HIGH· v4
8.8 HIGH· v3
N/A· v2
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker...Show more
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.Show less
1Advantech
1Adam 5550 Firmware
Jun 17, 2026
Sep 27, 2024
8.7 HIGH· v4
6.1 MEDIUM· v3
N/A· v2
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generat...Show more
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.Show less
1Advantech
1Adam 5550 Firmware
Jun 17, 2026
Sep 27, 2024
6.8 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.