AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Advantech
AD
Platform

Advantech

Industrial PCs, embedded computing, IO modules, and industrial Ethernet for IIoT and industrial automation applications.

https://www.advantech.com →
290
Total CVEs
0
Resources
65
CRIT
140
HIGH
84
MED
1
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
290 entries
CVE-2025-34256CRITICAL

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.

Dec 5, 2025
9.8
CVE-2022-50593CRITICAL

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

Nov 6, 2025
9.8
CVE-2022-50591CRITICAL

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.

Nov 6, 2025
9.8
CVE-2024-50375CRITICAL

A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point.

Nov 26, 2024
9.8
CVE-2024-50374CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "capture_packages" operation.

Nov 26, 2024
9.8
CVE-2024-50373CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "restore_config_from_utility" operation.

Nov 26, 2024
9.8
CVE-2024-50372CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "backup_config_to_utility" operation.

Nov 26, 2024
9.8
CVE-2024-50371CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "wlan_scan" operation.

Nov 26, 2024
9.8
CVE-2024-50370CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "cfg_cmd_set_eth_conf" operation.

Nov 26, 2024
9.8
CVE-2023-5642CRITICAL

Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information.

Oct 18, 2023
9.8
CVE-2023-1437CRITICAL

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.

Aug 2, 2023
9.8
CVE-2023-2611CRITICAL

Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.

Jun 22, 2023
9.8
CVE-2022-3386CRITICAL

Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.

Oct 27, 2022
9.8
CVE-2022-3385CRITICAL

Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.

Oct 27, 2022
9.8
CVE-2021-38389CRITICAL

Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.

Oct 18, 2021
9.8
CVE-2021-33023CRITICAL

Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.

Oct 18, 2021
9.8
CVE-2021-38408CRITICAL

A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

Sep 9, 2021
9.8
CVE-2021-21805CRITICAL

An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability.

Aug 5, 2021
9.8
CVE-2021-21804CRITICAL

A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafted HTTP request to trigger this vulnerability.

Jul 16, 2021
9.8
CVE-2019-18235CRITICAL

Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.

Mar 17, 2021
9.8
CVE-2021-22658CRITICAL

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.

Feb 11, 2021
9.8
CVE-2021-22652CRITICAL

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.

Feb 11, 2021
9.8
CVE-2020-16245CRITICAL

Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

Aug 25, 2020
9.8
CVE-2020-14503CRITICAL

Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an attacker to remotely execute arbitrary code.

Jul 15, 2020
9.8
CVE-2020-14501CRITICAL

Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrator credentials in plain text. An attacker may also delete the administrator account.

Jul 15, 2020
9.8
CVE-2020-14507CRITICAL

Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

Jul 15, 2020
9.8
CVE-2020-14505CRITICAL

Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.

Jul 15, 2020
9.8
CVE-2020-14497CRITICAL

Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.

Jul 15, 2020
9.8
CVE-2020-12022CRITICAL

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially crafted input into memory where it can be executed.

May 8, 2020
9.8
CVE-2020-12006CRITICAL

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

May 8, 2020
9.8
CVE-2020-12002CRITICAL

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

May 8, 2020
9.8
CVE-2020-10638CRITICAL

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

May 8, 2020
9.8
CVE-2019-18257CRITICAL

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

Dec 17, 2019
9.8
CVE-2019-3951CRITICAL

Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling IOCTL 70533 RPC messages.

Dec 12, 2019
9.8
CVE-2019-13551CRITICAL

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.

Oct 31, 2019
9.8
CVE-2019-13547CRITICAL

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.

Oct 31, 2019
9.8
CVE-2019-3975CRITICAL

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCTL 70603 RPC message.

Sep 10, 2019
9.8
CVE-2019-3954CRITICAL

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.

Jun 19, 2019
9.8
CVE-2019-3953CRITICAL

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 10012 RPC call.

Jun 18, 2019
9.8
CVE-2019-3940CRITICAL

Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.

Apr 9, 2019
9.8
CVE-2019-6552CRITICAL

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.

Apr 5, 2019
9.8
CVE-2019-6550CRITICAL

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a lack of proper validation of the length of user-supplied data, may allow remote code execution.

Apr 5, 2019
9.8
CVE-2018-14816CRITICAL

Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker to execute arbitrary code.

Oct 23, 2018
9.8
CVE-2018-14806CRITICAL

Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code.

Oct 23, 2018
9.8
CVE-2018-8845CRITICAL

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a heap-based buffer overflow vulnerability has been identified, which may allow an attacker to execute arbitrary code.

May 15, 2018
9.8
CVE-2018-7505CRITICAL

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization, which may allow an attacker to execute arbitrary code.

May 15, 2018
9.8
CVE-2018-7499CRITICAL

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several stack-based buffer overflow vulnerabilities have been identified, which may allow an attacker to execute arbitrary code.

May 15, 2018
9.8
CVE-2018-7497CRITICAL

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several untrusted pointer dereference vulnerabilities have been identified, which may allow an attacker to execute arbitrary code.

May 15, 2018
9.8
CVE-2018-10589CRITICAL

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to execute arbitrary code.

May 15, 2018
9.8
CVE-2018-6911CRITICAL

The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).

Feb 13, 2018
9.8
CVE-2017-16724CRITICAL

A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple instances of a vulnerability that allows too much data to be written to a location on the stack.

Jan 5, 2018
9.8
CVE-2017-12708CRITICAL

An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities that allow invalid locations to be referenced for the memory buffer, which may allow an attacker to execute arbitrary code or cause the system to crash.

Aug 30, 2017
9.8
CVE-2017-12706CRITICAL

A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

Aug 30, 2017
9.8
CVE-2017-12698CRITICAL

An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that could allow remote code execution.

Aug 30, 2017
9.8
CVE-2017-7909CRITICAL

A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.

May 6, 2017
9.8
CVE-2017-5154CRITICAL

An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.

Feb 13, 2017
9.8
CVE-2016-2275CRITICAL

The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.

Feb 21, 2016
9.8
CVE-2016-0859CRITICAL

Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted RPC request.

Jan 15, 2016
9.8
CVE-2016-0857CRITICAL

Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

Jan 15, 2016
9.8
CVE-2016-0856CRITICAL

Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

Jan 15, 2016
9.8
CVE-2016-0854CRITICAL

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

Jan 15, 2016
9.8
CVE-2015-7938CRITICAL

Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors.

Jan 9, 2016
9.8
CVE-2017-5152CRITICAL

An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICATION BYPASS).

Feb 13, 2017
9.1
CVE-2023-4203CRITICAL

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.

Aug 8, 2023
9.0
CVE-2023-4202CRITICAL

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.

Aug 8, 2023
9.0
CVE-2015-6476HIGH

Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.

Nov 7, 2015
10.0
CVE-2014-9208HIGH

Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.

Sep 11, 2015
10.0
CVE-2014-8385HIGH

Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 13, 2015
10.0
CVE-2012-0243HIGH

Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.

Feb 21, 2012
10.0
CVE-2012-0242HIGH

Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.

Feb 21, 2012
10.0
CVE-2012-0240HIGH

GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 21, 2012
10.0
CVE-2012-0238HIGH

Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 21, 2012
10.0
CVE-2011-4526HIGH

Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long string value in unspecified parameters.

Feb 21, 2012
10.0
CVE-2011-4525HIGH

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.

Feb 21, 2012
10.0
CVE-2011-4524HIGH

Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.

Feb 21, 2012
10.0
CVE-2011-1914HIGH

Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server before 3.01.010, and Modbus TCP OPC Server before 3.01.010 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 21, 2012
10.0
CVE-2011-4041HIGH

webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.

Feb 6, 2012
10.0
CVE-2011-0488HIGH

Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long request to TCP port 80.

Jan 18, 2011
10.0
CVE-2008-5848HIGH

The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity.

Jan 6, 2009
10.0
CVE-2011-0340HIGH

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

May 4, 2011
9.3
CVE-2014-8387HIGH

cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

Nov 20, 2014
9.0
CVE-2014-2366HIGH

upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.

Jul 19, 2014
9.0
CVE-2025-14849HIGH

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Dec 18, 2025
8.8
CVE-2025-53515HIGH

A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.

Jul 11, 2025
8.8
CVE-2025-53475HIGH

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.

Jul 11, 2025
8.8
CVE-2025-52577HIGH

A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.

Jul 11, 2025
8.8
CVE-2024-38308HIGH

Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.

Sep 27, 2024
8.8
CVE-2023-3983HIGH

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.

Jul 31, 2023
8.8
CVE-2023-3256HIGH

Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

Jun 22, 2023
8.8
CVE-2023-2575HIGH

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.

May 8, 2023
8.8
CVE-2023-2574HIGH

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.

May 8, 2023
8.8
CVE-2023-2573HIGH

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.

May 8, 2023
8.8
CVE-2021-40396HIGH

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
8.8
CVE-2021-40389HIGH

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
8.8
CVE-2021-40388HIGH

A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
8.8
CVE-2021-21917HIGH

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

Dec 22, 2021
8.8
CVE-2021-21916HIGH

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

Dec 22, 2021
8.8
CVE-2021-21915HIGH

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

Dec 22, 2021
8.8
CVE-2020-13555HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-13553HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-13552HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-13551HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-12026HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

May 8, 2020
8.8
CVE-2020-10607HIGH

In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

Mar 27, 2020
8.8
CVE-2019-10961HIGH

In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.

Aug 2, 2019
8.8
CVE-2018-15704HIGH

Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp.

Oct 22, 2018
8.8
CVE-2017-12704HIGH

A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to the heap-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

Aug 30, 2017
8.8
CVE-2017-12702HIGH

An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an attacker to execute arbitrary code.

Aug 30, 2017
8.8
CVE-2015-3946HIGH

Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Jan 15, 2016
8.8
CVE-2025-14850HIGH

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

Dec 18, 2025
8.1
CVE-2016-0858HIGH

Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.

Jan 15, 2016
8.1
CVE-2015-6467HIGH

Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.

Jan 15, 2016
8.1
CVE-2015-3947HIGH

SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Jan 15, 2016
8.1
CVE-2024-39275HIGH

Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.

Sep 27, 2024
8.0
CVE-2024-28948HIGH

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.

Sep 27, 2024
8.0
CVE-2025-14252HIGH

An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior.

Dec 16, 2025
7.8
CVE-2021-40397HIGH

A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
7.8
CVE-2021-21912HIGH

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Dec 22, 2021
7.8
CVE-2021-21911HIGH

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Dec 22, 2021
7.8
CVE-2021-21910HIGH

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Dec 22, 2021
7.8
CVE-2020-13554HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Mar 3, 2021
7.8
CVE-2020-16229HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a type confusion condition, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16217HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16215HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16213HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16207HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2018-14828HIGH

Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level.

Oct 23, 2018
7.8
CVE-2018-8841HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files when read access should only be given to the user.

May 15, 2018
7.8
CVE-2017-5175HIGH

Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code.

May 9, 2018
7.8
CVE-2018-8837HIGH

Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.

Apr 25, 2018
7.8
CVE-2018-8835HIGH

Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

Apr 25, 2018
7.8
CVE-2018-8833HIGH

Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

Apr 25, 2018
7.8
CVE-2017-12705HIGH

A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer overflow, which may crash the process and allow an attacker to execute arbitrary code.

Oct 25, 2017
7.8
CVE-2017-12717HIGH

An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.

Aug 30, 2017
7.8
CVE-2017-12713HIGH

An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.

Aug 30, 2017
7.8
CVE-2017-12711HIGH

An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administrative privileges.

Aug 30, 2017
7.8
CVE-2016-9353HIGH

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.

Feb 13, 2017
7.8
CVE-2013-1627HIGH

Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.

Mar 11, 2013
7.8
CVE-2020-13550HIGH

A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

Feb 17, 2021
7.7
CVE-2025-48891HIGH

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition.

Jul 11, 2025
7.6
CVE-2025-13373HIGH

Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

Dec 4, 2025
7.5
CVE-2022-50594HIGH

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.

Nov 6, 2025
7.5
CVE-2023-52335HIGH

Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863.

Nov 22, 2024
7.5
CVE-2022-3323HIGH

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

Sep 27, 2022
7.5
CVE-2019-18231HIGH

Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.

Mar 17, 2021
7.5
CVE-2021-22656HIGH

Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.

Feb 11, 2021
7.5
CVE-2021-22654HIGH

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.

Feb 11, 2021
7.5
CVE-2020-14499HIGH

Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.

Jul 15, 2020
7.5
CVE-2020-12018HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.

May 8, 2020
7.5
CVE-2020-12014HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.

May 8, 2020
7.5
CVE-2019-3942HIGH

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

Apr 1, 2020
7.5
CVE-2019-18227HIGH

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

Oct 31, 2019
7.5
CVE-2019-16901HIGH

Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.

Sep 26, 2019
7.5
CVE-2019-16900HIGH

Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.

Sep 26, 2019
7.5
CVE-2019-16899HIGH

In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfoThreadBase::GetNICInfo+0x0000000000512918.

Sep 26, 2019
7.5
CVE-2019-3941HIGH

Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

Apr 9, 2019
7.5
CVE-2019-6554HIGH

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.

Apr 5, 2019
7.5
CVE-2018-14820HIGH

Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing.

Oct 23, 2018
7.5
CVE-2018-7503HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to disclose sensitive information on the target.

May 15, 2018
7.5
CVE-2018-7501HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to disclose sensitive information from the host.

May 15, 2018
7.5
CVE-2018-7495HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an external control of file name or path vulnerability has been identified, which may allow an attacker to delete files.

May 15, 2018
7.5
CVE-2018-10590HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information exposure vulnerability through directory listing has been identified, which may allow an attacker to find important files that are not normally visible.

May 15, 2018
7.5
CVE-2017-16736HIGH

An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.

Jan 12, 2018
7.5
CVE-2017-16753HIGH

An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.

Jan 5, 2018
7.5
CVE-2017-16728HIGH

An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.

Jan 5, 2018
7.5
CVE-2017-12719HIGH

An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer within the program causing the application to become unavailable.

Nov 6, 2017
7.5
CVE-2017-12710HIGH

A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.

Aug 30, 2017
7.5
CVE-2016-9349HIGH

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.

Feb 13, 2017
7.5
CVE-2016-0860HIGH

Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service via a crafted RPC request.

Jan 15, 2016
7.5
CVE-2016-0855HIGH

Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors.

Jan 15, 2016
7.5
CVE-2016-0853HIGH

Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.

Jan 15, 2016
7.5
CVE-2016-0852HIGH

Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecified vectors.

Jan 15, 2016
7.5
CVE-2016-0851HIGH

Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.

Jan 15, 2016
7.5
CVE-2014-8386HIGH

Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.

Jan 20, 2015
7.5
CVE-2014-2368HIGH

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

Jul 19, 2014
7.5
CVE-2014-2367HIGH

The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

Jul 19, 2014
7.5
CVE-2014-2364HIGH

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

Jul 19, 2014
7.5
CVE-2012-0244HIGH

Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.

Feb 21, 2012
7.5
CVE-2012-0234HIGH

SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.

Feb 21, 2012
7.5
CVE-2011-4521HIGH

SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.

Feb 21, 2012
7.5
CVE-2024-50376HIGH

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.

Nov 26, 2024
7.3
CVE-2023-2866HIGH

If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.

Jun 7, 2023
7.3
CVE-2026-2670HIGH

A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Feb 18, 2026
7.2
CVE-2025-34239HIGH

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.

Nov 6, 2025
7.2
CVE-2022-50595HIGH

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

Nov 6, 2025
7.2
CVE-2022-50592HIGH

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

Nov 6, 2025
7.2
CVE-2024-50369HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "multiple_ssid_htm" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50368HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "basic_htm" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50367HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50366HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "applications_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50365HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "lan_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50364HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "export_log" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50363HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "mp_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50362HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "connection_profile_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50361HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "certificate_file_remove" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50360HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "snmp_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50359HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "scan_ap" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50358HIGH

A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.

Nov 26, 2024
7.2
CVE-2023-32628HIGH

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.

Jun 6, 2023
7.2
CVE-2023-32540HIGH

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.

Jun 6, 2023
7.2
CVE-2023-22450HIGH

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.

Jun 6, 2023
7.2
CVE-2014-8388HIGH

Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows remote attackers to execute arbitrary code via a crafted ip_address parameter in an HTML document.

Nov 21, 2014
7.2
CVE-2020-12010HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.

May 8, 2020
7.1
CVE-2017-7929HIGH

An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.

May 6, 2017
7.1
CVE-2016-9351HIGH

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.

Feb 13, 2017
7.0
CVE-2014-9202MEDIUM

Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitrary code via a crafted file that triggers long string arguments to functions.

Sep 28, 2015
6.9
CVE-2025-63701MEDIUM

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size matches the input buffer size, leading to invalid memory operations and heap corruption. This vulnerability can cause denial of service through application crashes and potentially lead to code execution in user space. Local access is required to exploit this vulnerability.

Nov 14, 2025
6.8
CVE-2014-0992MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the password parameter.

Sep 20, 2014
6.8
CVE-2014-0991MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projectname parameter.

Sep 20, 2014
6.8
CVE-2014-0990MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserName parameter.

Sep 20, 2014
6.8
CVE-2014-0989MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode2 parameter.

Sep 20, 2014
6.8
CVE-2014-0988MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode parameter.

Sep 20, 2014
6.8
CVE-2014-0987MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

Sep 20, 2014
6.8
CVE-2014-0986MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCmd parameter.

Sep 20, 2014
6.8
CVE-2014-0985MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName parameter.

Sep 20, 2014
6.8
CVE-2016-4525MEDIUM

Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.

Jun 25, 2016
6.6
CVE-2025-34247MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34246MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34245MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34244MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34243MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34242MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34241MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34240MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34238MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web user (www-data) can access.

Nov 6, 2025
6.5
CVE-2025-53509MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a command without proper sanitization, allowing arbitrary arguments to be injected. This can result in information disclosure, including sensitive database credentials.

Jul 11, 2025
6.5
CVE-2025-52459MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command without proper sanitization, allowing arbitrary arguments to be injected. This can result in information disclosure, including sensitive database credentials.

Jul 11, 2025
6.5
CVE-2024-50377MEDIUM

A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability is associated to the backup configuration functionality that by default encrypts the archives using a static password.

Nov 26, 2024
6.5
CVE-2023-4215MEDIUM

Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.

Oct 17, 2023
6.5
CVE-2022-3387MEDIUM

Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.

Oct 27, 2022
6.5
CVE-2021-32954MEDIUM

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.

Jun 18, 2021
6.5
CVE-2019-18229MEDIUM

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.

Oct 31, 2019
6.5
CVE-2018-15706MEDIUM

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.

Oct 31, 2018
6.5
CVE-2018-15705MEDIUM

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.

Oct 31, 2018
6.5
CVE-2017-16732MEDIUM

A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated attacker to specify an arbitrary address.

Jan 12, 2018
6.5
CVE-2014-2365MEDIUM

Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.

Jul 19, 2014
6.5
CVE-2012-1234MEDIUM

SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.

Feb 21, 2012
6.5
CVE-2024-2453MEDIUM

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

Mar 21, 2024
6.4
CVE-2012-0237MEDIUM

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.

Feb 21, 2012
6.4
CVE-2025-46268MEDIUM

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

Dec 18, 2025
6.3
CVE-2024-39364MEDIUM

Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without discrimination of origin or level of privileges of the user sending the commands.

Sep 27, 2024
6.3
CVE-2017-14016MEDIUM

A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

Nov 6, 2017
6.3
CVE-2021-21803MEDIUM

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Jul 16, 2021
6.1
CVE-2021-21802MEDIUM

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Jul 16, 2021
6.1
CVE-2021-21801MEDIUM

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Jul 16, 2021
6.1
CVE-2021-21800MEDIUM

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

Jul 16, 2021
6.1
CVE-2021-21799MEDIUM

Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

Jul 16, 2021
6.1
CVE-2021-32956MEDIUM

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.

Jun 18, 2021
6.1
CVE-2021-34540MEDIUM

Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.

Jun 11, 2021
6.1
CVE-2019-18233MEDIUM

In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.

Mar 17, 2021
6.1
CVE-2018-15703MEDIUM

Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser.

Oct 22, 2018
6.1
CVE-2018-10591MEDIUM

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can create a malicious web site, steal session cookies, and access data of authenticated users.

May 15, 2018
6.1
CVE-2012-1235MEDIUM

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.

Feb 21, 2012
6.0
CVE-2012-0235MEDIUM

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Feb 21, 2012
6.0
CVE-2024-37187MEDIUM

Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

Sep 27, 2024
5.7
CVE-2024-34542MEDIUM

Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

Sep 27, 2024
5.7
CVE-2020-16211MEDIUM

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

Aug 6, 2020
5.5
CVE-2025-34266MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and later rendered in the AddIns UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected AddIns entry, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34265MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings or detail views without proper HTML sanitation. An attacker can inject malicious script into one or more of these fields, which is then executed in the browser context of users who view or interact with the affected rule, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34264MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34263MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin configuration data and later rendered in the dashboard UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected dashboard, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34262MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without proper HTML sanitation. An attacker can inject malicious script into the device name, which is then executed in the browser context of users who view or interact with the affected device, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34261MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected device group, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34260MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sanitation. An attacker can inject malicious script into the schedule name, which is then executed in the browser context of users who view or interact with the affected schedule, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34259MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without HTML sanitzation. An attacker can inject malicious script into the map entry name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34258MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. An attacker can inject malicious script into the area name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34257MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34237MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

Nov 6, 2025
5.4
CVE-2025-34236MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

Nov 6, 2025
5.4
CVE-2025-53519MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.

Jul 11, 2025
5.4
CVE-2025-53397MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.

Jul 11, 2025
5.4
CVE-2025-41442MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.

Jul 11, 2025
5.4
CVE-2018-15707MEDIUM

Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

Oct 31, 2018
5.4
CVE-2015-3948MEDIUM

Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Jan 15, 2016
5.4
CVE-2018-5445MEDIUM

A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

Jan 25, 2018
5.3
CVE-2018-5443MEDIUM

A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.

Jan 25, 2018
5.3
CVE-2015-3943MEDIUM

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

Jan 15, 2016
5.3
CVE-2016-4528MEDIUM

Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.

Jun 25, 2016
5.0
CVE-2012-0241MEDIUM

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.

Feb 21, 2012
5.0
CVE-2012-0239MEDIUM

uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.

Feb 21, 2012
5.0
CVE-2012-0236MEDIUM

Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."

Feb 21, 2012
5.0
CVE-2016-5810MEDIUM

upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

May 2, 2017
4.9
CVE-2025-67653MEDIUM

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Dec 18, 2025
4.3
CVE-2025-14848MEDIUM

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Dec 18, 2025
4.3
CVE-2025-46704MEDIUM

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or normalized, potentially allowing an attacker to determine the existence of arbitrary files on the server.

Jul 11, 2025
4.3
CVE-2021-38431MEDIUM

An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.

Oct 15, 2021
4.3
CVE-2012-0233MEDIUM

Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.

Feb 21, 2012
4.3
CVE-2011-4523MEDIUM

Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Feb 21, 2012
4.3
CVE-2011-4522MEDIUM

Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Feb 21, 2012
4.3
CVE-2013-2299LOW

Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Aug 22, 2013
3.5
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2025-34256CRITICAL
9.8
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerab…Dec 5, 2025›
CVE-2022-50593CRITICAL
9.8
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2022-50591CRITICAL
9.8
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2024-50375CRITICAL
9.8
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devi…Nov 26, 2024›
CVE-2024-50374CRITICAL
9.8
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50373CRITICAL
9.8
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50372CRITICAL
9.8
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50371CRITICAL
9.8
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50370CRITICAL
9.8
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2023-5642CRITICAL
9.8
Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the s…Oct 18, 2023›
CVE-2023-1437CRITICAL
9.8
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers…Aug 2, 2023›
CVE-2023-2611CRITICAL
9.8
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not availab…Jun 22, 2023›
CVE-2022-3386CRITICAL
9.8
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An un…Oct 27, 2022›
CVE-2022-3385CRITICAL
9.8
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An un…Oct 27, 2022›
CVE-2021-38389CRITICAL
9.8
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which m…Oct 18, 2021›
CVE-2021-33023CRITICAL
9.8
Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which ma…Oct 18, 2021›
CVE-2021-38408CRITICAL
9.8
A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by…Sep 9, 2021›
CVE-2021-21805CRITICAL
9.8
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-See…Aug 5, 2021›
CVE-2021-21804CRITICAL
9.8
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advante…Jul 16, 2021›
CVE-2019-18235CRITICAL
9.8
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameter…Mar 17, 2021›
CVE-2021-22658CRITICAL
9.8
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an…Feb 11, 2021›
CVE-2021-22652CRITICAL
9.8
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authenticatio…Feb 11, 2021›
CVE-2020-16245CRITICAL
9.8
Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulner…Aug 25, 2020›
CVE-2020-14503CRITICAL
9.8
Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful …Jul 15, 2020›
CVE-2020-14501CRITICAL
9.8
Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-3…Jul 15, 2020›
CVE-2020-14507CRITICAL
9.8
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities th…Jul 15, 2020›
CVE-2020-14505CRITICAL
9.8
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in …Jul 15, 2020›
CVE-2020-14497CRITICAL
9.8
Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vu…Jul 15, 2020›
CVE-2020-12022CRITICAL
9.8
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerabili…May 8, 2020›
CVE-2020-12006CRITICAL
9.8
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal v…May 8, 2020›
CVE-2020-12002CRITICAL
9.8
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overfl…May 8, 2020›
CVE-2020-10638CRITICAL
9.8
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflo…May 8, 2020›
CVE-2019-18257CRITICAL
9.8
In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow v…Dec 17, 2019›
CVE-2019-3951CRITICAL
9.8
Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code o…Dec 12, 2019›
CVE-2019-13551CRITICAL
9.8
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a l…Oct 31, 2019›
CVE-2019-13547CRITICAL
9.8
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyon…Oct 31, 2019›
CVE-2019-3975CRITICAL
9.8
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated atta…Sep 10, 2019›
CVE-2019-3954CRITICAL
9.8
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated atta…Jun 19, 2019›
CVE-2019-3953CRITICAL
9.8
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated atta…Jun 18, 2019›
CVE-2019-3940CRITICAL
9.8
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unau…Apr 9, 2019›
CVE-2019-6552CRITICAL
9.8
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, cau…Apr 5, 2019›
CVE-2019-6550CRITICAL
9.8
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabil…Apr 5, 2019›
CVE-2018-14816CRITICAL
9.8
Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that h…Oct 23, 2018›
CVE-2018-14806CRITICAL
9.8
Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker…Oct 23, 2018›
CVE-2018-8845CRITICAL
9.8
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-7505CRITICAL
9.8
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-7499CRITICAL
9.8
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-7497CRITICAL
9.8
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-10589CRITICAL
9.8
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-6911CRITICAL
9.8
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to …Feb 13, 2018›
CVE-2017-16724CRITICAL
9.8
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to 8.3. The…Jan 5, 2018›
CVE-2017-12708CRITICAL
9.8
An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in A…Aug 30, 2017›
CVE-2017-12706CRITICAL
9.8
A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_201…Aug 30, 2017›
CVE-2017-12698CRITICAL
9.8
An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_201708…Aug 30, 2017›
CVE-2017-7909CRITICAL
9.8
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware…May 6, 2017›
CVE-2017-5154CRITICAL
9.8
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection …Feb 13, 2017›
CVE-2016-2275CRITICAL
9.8
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 …Feb 21, 2016›
CVE-2016-0859CRITICAL
9.8
Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to …Jan 15, 2016›
CVE-2016-0857CRITICAL
9.8
Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to exe…Jan 15, 2016›
CVE-2016-0856CRITICAL
9.8
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to ex…Jan 15, 2016›
CVE-2016-0854CRITICAL
9.8
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction scr…Jan 15, 2016›
CVE-2015-7938CRITICAL
9.8
Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authenti…Jan 9, 2016›
CVE-2017-5152CRITICAL
9.1
An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource…Feb 13, 2017›
CVE-2023-4203CRITICAL
9.0
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scri…Aug 8, 2023›
CVE-2023-4202CRITICAL
9.0
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scri…Aug 8, 2023›
CVE-2015-6476HIGH
10.0
Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98,…Nov 7, 2015›
CVE-2014-9208HIGH
10.0
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 a…Sep 11, 2015›
CVE-2014-8385HIGH
10.0
Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to …Feb 13, 2015›
CVE-2012-0243HIGH
10.0
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 all…Feb 21, 2012›
CVE-2012-0242HIGH
10.0
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to ex…Feb 21, 2012›
CVE-2012-0240HIGH
10.0
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authenticatio…Feb 21, 2012›
CVE-2012-0238HIGH
10.0
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote a…Feb 21, 2012›
CVE-2011-4526HIGH
10.0
Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote …Feb 21, 2012›
CVE-2011-4525HIGH
10.0
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitra…Feb 21, 2012›
CVE-2011-4524HIGH
10.0
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitr…Feb 21, 2012›
CVE-2011-1914HIGH
10.0
Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM O…Feb 21, 2012›
CVE-2011-4041HIGH
10.0
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or ob…Feb 6, 2012›
CVE-2011-0488HIGH
10.0
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as d…Jan 18, 2011›
CVE-2008-5848HIGH
10.0
The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remot…Jan 6, 2009›
CVE-2011-0340HIGH
9.3
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904…May 4, 2011›
CVE-2014-8387HIGH
9.0
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users…Nov 20, 2014›
CVE-2014-2366HIGH
9.0
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover creden…Jul 19, 2014›
CVE-2025-14849HIGH
8.8
Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to…Dec 18, 2025›
CVE-2025-53515HIGH
8.8
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution t…Jul 11, 2025›
CVE-2025-53475HIGH
8.8
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execut…Jul 11, 2025›
CVE-2025-52577HIGH
8.8
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution …Jul 11, 2025›
CVE-2024-38308HIGH
8.8
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received a…Sep 27, 2024›
CVE-2023-3983HIGH
8.8
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 buil…Jul 31, 2023›
CVE-2023-3256HIGH
8.8
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local …Jun 22, 2023›
CVE-2023-2575HIGH
8.8
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Ove…May 8, 2023›
CVE-2023-2574HIGH
8.8
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vul…May 8, 2023›
CVE-2023-2573HIGH
8.8
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vul…May 8, 2023›
CVE-2021-40396HIGH
8.8
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7…Jan 28, 2022›
CVE-2021-40389HIGH
8.8
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1…Jan 28, 2022›
CVE-2021-40388HIGH
8.8
A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafte…Jan 28, 2022›
CVE-2021-21917HIGH
8.8
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet …Dec 22, 2021›
CVE-2021-21916HIGH
8.8
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet …Dec 22, 2021›
CVE-2021-21915HIGH
8.8
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet …Dec 22, 2021›
CVE-2020-13555HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-13553HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-13552HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-13551HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-12026HIGH
8.8
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal v…May 8, 2020›
CVE-2020-10607HIGH
8.8
In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused…Mar 27, 2020›
CVE-2019-10961HIGH
8.8
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR fil…Aug 2, 2019›
CVE-2018-15704HIGH
8.8
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote…Oct 22, 2018›
CVE-2017-12704HIGH
8.8
A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_2017…Aug 30, 2017›
CVE-2017-12702HIGH
8.8
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to…Aug 30, 2017›
CVE-2015-3946HIGH
8.8
Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote atta…Jan 15, 2016›
CVE-2025-14850HIGH
8.1
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delet…Dec 18, 2025›
CVE-2016-0858HIGH
8.1
Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code o…Jan 15, 2016›
CVE-2015-6467HIGH
8.1
Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involvi…Jan 15, 2016›
CVE-2015-3947HIGH
8.1
SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to e…Jan 15, 2016›
CVE-2024-39275HIGH
8.0
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is…Sep 27, 2024›
CVE-2024-28948HIGH
8.0
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacke…Sep 27, 2024›
CVE-2025-14252HIGH
7.8
An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to rea…Dec 16, 2025›
CVE-2021-40397HIGH
7.8
A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.…Jan 28, 2022›
CVE-2021-21912HIGH
7.8
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-S…Dec 22, 2021›
CVE-2021-21911HIGH
7.8
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-S…Dec 22, 2021›
CVE-2021-21910HIGH
7.8
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-S…Dec 22, 2021›
CVE-2020-13554HIGH
7.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Mar 3, 2021›
CVE-2020-16229HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project …Aug 6, 2020›
CVE-2020-16217HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by…Aug 6, 2020›
CVE-2020-16215HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project …Aug 6, 2020›
CVE-2020-16213HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project …Aug 6, 2020›
CVE-2020-16207HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow v…Aug 6, 2020›
CVE-2018-14828HIGH
7.8
Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may …Oct 23, 2018›
CVE-2018-8841HIGH
7.8
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2017-5175HIGH
7.8
Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attack…May 9, 2018›
CVE-2018-8837HIGH
7.8
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may c…Apr 25, 2018›
CVE-2018-8835HIGH
7.8
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by process…Apr 25, 2018›
CVE-2018-8833HIGH
7.8
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior ca…Apr 25, 2018›
CVE-2017-12705HIGH
7.8
A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project …Oct 25, 2017›
CVE-2017-12717HIGH
7.8
An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8…Aug 30, 2017›
CVE-2017-12713HIGH
7.8
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess…Aug 30, 2017›
CVE-2017-12711HIGH
7.8
An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2…Aug 30, 2017›
CVE-2016-9353HIGH
7.8
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is …Feb 13, 2017›
CVE-2013-1627HIGH
7.8
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Adva…Mar 11, 2013›
CVE-2020-13550HIGH
7.7
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess…Feb 17, 2021›
CVE-2025-48891HIGH
7.6
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.che…Jul 11, 2025›
CVE-2025-13373HIGH
7.5
Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requ…Dec 4, 2025›
CVE-2022-50594HIGH
7.5
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2023-52335HIGH
7.5
Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulner…Nov 22, 2024›
CVE-2022-3323HIGH
7.5
An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the C…Sep 27, 2022›
CVE-2019-18231HIGH
7.5
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear t…Mar 17, 2021›
CVE-2021-22656HIGH
7.5
Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allo…Feb 11, 2021›
CVE-2021-22654HIGH
7.5
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an…Feb 11, 2021›
CVE-2020-14499HIGH
7.5
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful ex…Jul 15, 2020›
CVE-2020-12018HIGH
7.5
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exi…May 8, 2020›
CVE-2020-12014HIGH
7.5
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized an…May 8, 2020›
CVE-2019-3942HIGH
7.5
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote…Apr 1, 2020›
CVE-2019-18227HIGH
7.5
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclos…Oct 31, 2019›
CVE-2019-16901HIGH
7.5
Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown…Sep 26, 2019›
CVE-2019-16900HIGH
7.5
Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x0000…Sep 26, 2019›
CVE-2019-16899HIGH
7.5
In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starti…Sep 26, 2019›
CVE-2019-3941HIGH
7.5
Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOC…Apr 9, 2019›
CVE-2019-6554HIGH
7.5
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may al…Apr 5, 2019›
CVE-2018-14820HIGH
7.5
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control o…Oct 23, 2018›
CVE-2018-7503HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-7501HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-7495HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-10590HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2017-16736HIGH
7.5
An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versi…Jan 12, 2018›
CVE-2017-16753HIGH
7.5
An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebA…Jan 5, 2018›
CVE-2017-16728HIGH
7.5
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. …Jan 5, 2018›
CVE-2017-12719HIGH
7.5
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_…Nov 6, 2017›
CVE-2017-12710HIGH
7.5
A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By subm…Aug 30, 2017›
CVE-2016-9349HIGH
7.5
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could trav…Feb 13, 2017›
CVE-2016-0860HIGH
7.5
Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers …Jan 15, 2016›
CVE-2016-0855HIGH
7.5
Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list …Jan 15, 2016›
CVE-2016-0853HIGH
7.5
Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted i…Jan 15, 2016›
CVE-2016-0852HIGH
7.5
Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirem…Jan 15, 2016›
CVE-2016-0851HIGH
7.5
Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds m…Jan 15, 2016›
CVE-2014-8386HIGH
7.5
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers t…Jan 20, 2015›
CVE-2014-2368HIGH
7.5
The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows rem…Jul 19, 2014›
CVE-2014-2367HIGH
7.5
The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAcce…Jul 19, 2014›
CVE-2014-2364HIGH
7.5
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to ex…Jul 19, 2014›
CVE-2012-0244HIGH
7.5
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attac…Feb 21, 2012›
CVE-2012-0234HIGH
7.5
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to ex…Feb 21, 2012›
CVE-2011-4521HIGH
7.5
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to ex…Feb 21, 2012›
CVE-2024-50376HIGH
7.3
A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was …Nov 26, 2024›
CVE-2023-2866HIGH
7.3
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Ad…Jun 7, 2023›
CVE-2026-2670HIGH
7.2
A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown functio…Feb 18, 2026›
CVE-2025-34239HIGH
7.2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppMana…Nov 6, 2025›
CVE-2022-50595HIGH
7.2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2022-50592HIGH
7.2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2024-50369HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50368HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50367HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50366HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50365HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50364HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50363HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50362HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50361HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50360HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50359HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50358HIGH
7.2
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the followin…Nov 26, 2024›
CVE-2023-32628HIGH
7.2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability t…Jun 6, 2023›
CVE-2023-32540HIGH
7.2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, w…Jun 6, 2023›
CVE-2023-22450HIGH
7.2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability tha…Jun 6, 2023›
CVE-2014-8388HIGH
7.2
Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows r…Nov 21, 2014›
CVE-2020-12010HIGH
7.1
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal v…May 8, 2020›
CVE-2017-7929HIGH
7.1
An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The ab…May 6, 2017›
CVE-2016-9351HIGH
7.0
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversa…Feb 13, 2017›
CVE-2014-9202MEDIUM
6.9
Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_2…Sep 28, 2015›
CVE-2025-63701MEDIUM
6.8
A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH…Nov 14, 2025›
CVE-2014-0992MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0991MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0990MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0989MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0988MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0987MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0986MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0985MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2016-4525MEDIUM
6.6
Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated u…Jun 25, 2016›
CVE-2025-34247MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksCon…Nov 6, 2025›
CVE-2025-34246MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevali…Nov 6, 2025›
CVE-2025-34245MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandal…Nov 6, 2025›
CVE-2025-34244MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRules…Nov 6, 2025›
CVE-2025-34243MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRules…Nov 6, 2025›
CVE-2025-34242MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetwork…Nov 6, 2025›
CVE-2025-34241MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceC…Nov 6, 2025›
CVE-2025-34240MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManageme…Nov 6, 2025›
CVE-2025-34238MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandalon…Nov 6, 2025›
CVE-2025-53509MEDIUM
6.5
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.…Jul 11, 2025›
CVE-2025-52459MEDIUM
6.5
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.back…Jul 11, 2025›
CVE-2024-50377MEDIUM
6.5
A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufacture…Nov 26, 2024›
CVE-2023-4215MEDIUM
6.5
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized a…Oct 17, 2023›
CVE-2022-3387MEDIUM
6.5
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthori…Oct 27, 2022›
CVE-2021-32954MEDIUM
6.5
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may…Jun 18, 2021›
CVE-2019-18229MEDIUM
6.5
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input caus…Oct 31, 2019›
CVE-2018-15706MEDIUM
6.5
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read…Oct 31, 2018›
CVE-2018-15705MEDIUM
6.5
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to writ…Oct 31, 2018›
CVE-2017-16732MEDIUM
6.5
A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows…Jan 12, 2018›
CVE-2014-2365MEDIUM
6.5
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to cre…Jul 19, 2014›
CVE-2012-1234MEDIUM
6.5
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to…Feb 21, 2012›
CVE-2024-2453MEDIUM
6.4
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authen…Mar 21, 2024›
CVE-2012-0237MEDIUM
6.4
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing …Feb 21, 2012›
CVE-2025-46268MEDIUM
6.3
Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute ar…Dec 18, 2025›
CVE-2024-39364MEDIUM
6.3
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. Th…Sep 27, 2024›
CVE-2017-14016MEDIUM
6.3
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_201…Nov 6, 2017›
CVE-2021-21803MEDIUM
6.1
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-Se…Jul 16, 2021›
CVE-2021-21802MEDIUM
6.1
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-Se…Jul 16, 2021›
CVE-2021-21801MEDIUM
6.1
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-Se…Jul 16, 2021›
CVE-2021-21800MEDIUM
6.1
Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-S…Jul 16, 2021›
CVE-2021-21799MEDIUM
6.1
Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech …Jul 16, 2021›
CVE-2021-32956MEDIUM
6.1
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an …Jun 18, 2021›
CVE-2021-34540MEDIUM
6.1
Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WAD…Jun 11, 2021›
CVE-2019-18233MEDIUM
6.1
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neu…Mar 17, 2021›
CVE-2018-15703MEDIUM
6.1
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnera…Oct 22, 2018›
CVE-2018-10591MEDIUM
6.1
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2012-1235MEDIUM
6.0
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote au…Feb 21, 2012›
CVE-2012-0235MEDIUM
6.0
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows re…Feb 21, 2012›
CVE-2024-37187MEDIUM
5.7
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 enc…Sep 27, 2024›
CVE-2024-34542MEDIUM
5.7
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device…Sep 27, 2024›
CVE-2020-16211MEDIUM
5.5
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability m…Aug 6, 2020›
CVE-2025-34266MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34265MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34264MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34263MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34262MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34261MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34260MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34259MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34258MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34257MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34237MEDIUM
5.4
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerab…Nov 6, 2025›
CVE-2025-34236MEDIUM
5.4
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerab…Nov 6, 2025›
CVE-2025-53519MEDIUM
5.4
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a …Jul 11, 2025›
CVE-2025-53397MEDIUM
5.4
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a …Jul 11, 2025›
CVE-2025-41442MEDIUM
5.4
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a …Jul 11, 2025›
CVE-2018-15707MEDIUM
5.4
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp pag…Oct 31, 2018›
CVE-2015-3948MEDIUM
5.4
Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticat…Jan 15, 2016›
CVE-2018-5445MEDIUM
5.3
A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. …Jan 25, 2018›
CVE-2018-5443MEDIUM
5.3
A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. W…Jan 25, 2018›
CVE-2015-3943MEDIUM
5.3
Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about…Jan 15, 2016›
CVE-2016-4528MEDIUM
5.0
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of s…Jun 25, 2016›
CVE-2012-0241MEDIUM
5.0
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory…Feb 21, 2012›
CVE-2012-0239MEDIUM
5.0
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication,…Feb 21, 2012›
CVE-2012-0236MEDIUM
5.0
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information…Feb 21, 2012›
CVE-2016-5810MEDIUM
4.9
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators …May 2, 2017›
CVE-2025-67653MEDIUM
4.3
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to deter…Dec 18, 2025›
CVE-2025-14848MEDIUM
4.3
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker…Dec 18, 2025›
CVE-2025-46704MEDIUM
4.3
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow…Jul 11, 2025›
CVE-2021-38431MEDIUM
4.3
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functi…Oct 15, 2021›
CVE-2012-0233MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote at…Feb 21, 2012›
CVE-2011-4523MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 al…Feb 21, 2012›
CVE-2011-4522MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 a…Feb 21, 2012›
CVE-2013-2299LOW
3.5
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before…Aug 22, 2013›