Skip to main content

Vendor archive

advantech CVEs

Beta · best-effort

378 CVEs tagged to vendor advantech104 Critical, 160 High, 112 Medium, 2 Low, 0 Unrated.

CVE-2025-67653

Published Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46268

Published Dec 18, 2025

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14850

Published Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

CVSS 7.2 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-14849

Published Dec 18, 2025

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-14848

Published Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-34266

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenti…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34265

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user cre…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34264

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user ad…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34263

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an auth…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34262

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticat…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34261

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user cr…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34260

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34259

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated us…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34258

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34257

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user c…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34256

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-64302

Published Nov 6, 2025

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62630

Published Nov 6, 2025

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permi…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59171

Published Nov 6, 2025

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permi…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58423

Published Nov 6, 2025

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34247

Published Nov 6, 2025

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34246

Published Nov 6, 2025

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged obser…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34245

Published Nov 6, 2025

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privilege…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 378 CVEsPage 1 of 16