AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Advantech
AD
Platform

Advantech

Industrial PCs, embedded computing, IO modules, and industrial Ethernet for IIoT and industrial automation applications.

https://www.advantech.com →
290
Total CVEs
0
Resources
65
CRIT
140
HIGH
84
MED
1
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
84 / 290
CVE-2014-9202MEDIUM

Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitrary code via a crafted file that triggers long string arguments to functions.

Sep 28, 2015
6.9
CVE-2025-63701MEDIUM

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size matches the input buffer size, leading to invalid memory operations and heap corruption. This vulnerability can cause denial of service through application crashes and potentially lead to code execution in user space. Local access is required to exploit this vulnerability.

Nov 14, 2025
6.8
CVE-2014-0992MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the password parameter.

Sep 20, 2014
6.8
CVE-2014-0991MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projectname parameter.

Sep 20, 2014
6.8
CVE-2014-0990MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserName parameter.

Sep 20, 2014
6.8
CVE-2014-0989MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode2 parameter.

Sep 20, 2014
6.8
CVE-2014-0988MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode parameter.

Sep 20, 2014
6.8
CVE-2014-0987MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

Sep 20, 2014
6.8
CVE-2014-0986MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCmd parameter.

Sep 20, 2014
6.8
CVE-2014-0985MEDIUM

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName parameter.

Sep 20, 2014
6.8
CVE-2016-4525MEDIUM

Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.

Jun 25, 2016
6.6
CVE-2025-34247MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34246MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34245MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34244MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34243MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34242MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34241MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34240MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Nov 6, 2025
6.5
CVE-2025-34238MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web user (www-data) can access.

Nov 6, 2025
6.5
CVE-2025-53509MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a command without proper sanitization, allowing arbitrary arguments to be injected. This can result in information disclosure, including sensitive database credentials.

Jul 11, 2025
6.5
CVE-2025-52459MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command without proper sanitization, allowing arbitrary arguments to be injected. This can result in information disclosure, including sensitive database credentials.

Jul 11, 2025
6.5
CVE-2024-50377MEDIUM

A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability is associated to the backup configuration functionality that by default encrypts the archives using a static password.

Nov 26, 2024
6.5
CVE-2023-4215MEDIUM

Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.

Oct 17, 2023
6.5
CVE-2022-3387MEDIUM

Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.

Oct 27, 2022
6.5
CVE-2021-32954MEDIUM

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.

Jun 18, 2021
6.5
CVE-2019-18229MEDIUM

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.

Oct 31, 2019
6.5
CVE-2018-15706MEDIUM

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.

Oct 31, 2018
6.5
CVE-2018-15705MEDIUM

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.

Oct 31, 2018
6.5
CVE-2017-16732MEDIUM

A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated attacker to specify an arbitrary address.

Jan 12, 2018
6.5
CVE-2014-2365MEDIUM

Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.

Jul 19, 2014
6.5
CVE-2012-1234MEDIUM

SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.

Feb 21, 2012
6.5
CVE-2024-2453MEDIUM

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

Mar 21, 2024
6.4
CVE-2012-0237MEDIUM

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.

Feb 21, 2012
6.4
CVE-2025-46268MEDIUM

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

Dec 18, 2025
6.3
CVE-2024-39364MEDIUM

Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without discrimination of origin or level of privileges of the user sending the commands.

Sep 27, 2024
6.3
CVE-2017-14016MEDIUM

A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

Nov 6, 2017
6.3
CVE-2021-21803MEDIUM

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Jul 16, 2021
6.1
CVE-2021-21802MEDIUM

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Jul 16, 2021
6.1
CVE-2021-21801MEDIUM

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Jul 16, 2021
6.1
CVE-2021-21800MEDIUM

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

Jul 16, 2021
6.1
CVE-2021-21799MEDIUM

Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

Jul 16, 2021
6.1
CVE-2021-32956MEDIUM

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.

Jun 18, 2021
6.1
CVE-2021-34540MEDIUM

Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.

Jun 11, 2021
6.1
CVE-2019-18233MEDIUM

In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.

Mar 17, 2021
6.1
CVE-2018-15703MEDIUM

Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser.

Oct 22, 2018
6.1
CVE-2018-10591MEDIUM

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can create a malicious web site, steal session cookies, and access data of authenticated users.

May 15, 2018
6.1
CVE-2012-1235MEDIUM

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.

Feb 21, 2012
6.0
CVE-2012-0235MEDIUM

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Feb 21, 2012
6.0
CVE-2024-37187MEDIUM

Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

Sep 27, 2024
5.7
CVE-2024-34542MEDIUM

Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

Sep 27, 2024
5.7
CVE-2020-16211MEDIUM

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

Aug 6, 2020
5.5
CVE-2025-34266MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and later rendered in the AddIns UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected AddIns entry, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34265MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings or detail views without proper HTML sanitation. An attacker can inject malicious script into one or more of these fields, which is then executed in the browser context of users who view or interact with the affected rule, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34264MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34263MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin configuration data and later rendered in the dashboard UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected dashboard, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34262MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without proper HTML sanitation. An attacker can inject malicious script into the device name, which is then executed in the browser context of users who view or interact with the affected device, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34261MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected device group, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34260MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sanitation. An attacker can inject malicious script into the schedule name, which is then executed in the browser context of users who view or interact with the affected schedule, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34259MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without HTML sanitzation. An attacker can inject malicious script into the map entry name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34258MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. An attacker can inject malicious script into the area name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34257MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim.

Dec 5, 2025
5.4
CVE-2025-34237MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

Nov 6, 2025
5.4
CVE-2025-34236MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

Nov 6, 2025
5.4
CVE-2025-53519MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.

Jul 11, 2025
5.4
CVE-2025-53397MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.

Jul 11, 2025
5.4
CVE-2025-41442MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities.

Jul 11, 2025
5.4
CVE-2018-15707MEDIUM

Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

Oct 31, 2018
5.4
CVE-2015-3948MEDIUM

Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Jan 15, 2016
5.4
CVE-2018-5445MEDIUM

A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

Jan 25, 2018
5.3
CVE-2018-5443MEDIUM

A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.

Jan 25, 2018
5.3
CVE-2015-3943MEDIUM

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

Jan 15, 2016
5.3
CVE-2016-4528MEDIUM

Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.

Jun 25, 2016
5.0
CVE-2012-0241MEDIUM

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.

Feb 21, 2012
5.0
CVE-2012-0239MEDIUM

uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.

Feb 21, 2012
5.0
CVE-2012-0236MEDIUM

Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."

Feb 21, 2012
5.0
CVE-2016-5810MEDIUM

upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

May 2, 2017
4.9
CVE-2025-67653MEDIUM

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Dec 18, 2025
4.3
CVE-2025-14848MEDIUM

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Dec 18, 2025
4.3
CVE-2025-46704MEDIUM

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or normalized, potentially allowing an attacker to determine the existence of arbitrary files on the server.

Jul 11, 2025
4.3
CVE-2021-38431MEDIUM

An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.

Oct 15, 2021
4.3
CVE-2012-0233MEDIUM

Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.

Feb 21, 2012
4.3
CVE-2011-4523MEDIUM

Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Feb 21, 2012
4.3
CVE-2011-4522MEDIUM

Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Feb 21, 2012
4.3
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2014-9202MEDIUM
6.9
Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_2…Sep 28, 2015›
CVE-2025-63701MEDIUM
6.8
A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH…Nov 14, 2025›
CVE-2014-0992MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0991MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0990MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0989MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0988MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0987MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0986MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2014-0985MEDIUM
6.8
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote a…Sep 20, 2014›
CVE-2016-4525MEDIUM
6.6
Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated u…Jun 25, 2016›
CVE-2025-34247MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksCon…Nov 6, 2025›
CVE-2025-34246MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevali…Nov 6, 2025›
CVE-2025-34245MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandal…Nov 6, 2025›
CVE-2025-34244MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRules…Nov 6, 2025›
CVE-2025-34243MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRules…Nov 6, 2025›
CVE-2025-34242MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetwork…Nov 6, 2025›
CVE-2025-34241MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceC…Nov 6, 2025›
CVE-2025-34240MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManageme…Nov 6, 2025›
CVE-2025-34238MEDIUM
6.5
Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandalon…Nov 6, 2025›
CVE-2025-53509MEDIUM
6.5
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.…Jul 11, 2025›
CVE-2025-52459MEDIUM
6.5
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.back…Jul 11, 2025›
CVE-2024-50377MEDIUM
6.5
A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufacture…Nov 26, 2024›
CVE-2023-4215MEDIUM
6.5
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized a…Oct 17, 2023›
CVE-2022-3387MEDIUM
6.5
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthori…Oct 27, 2022›
CVE-2021-32954MEDIUM
6.5
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may…Jun 18, 2021›
CVE-2019-18229MEDIUM
6.5
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input caus…Oct 31, 2019›
CVE-2018-15706MEDIUM
6.5
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read…Oct 31, 2018›
CVE-2018-15705MEDIUM
6.5
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to writ…Oct 31, 2018›
CVE-2017-16732MEDIUM
6.5
A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows…Jan 12, 2018›
CVE-2014-2365MEDIUM
6.5
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to cre…Jul 19, 2014›
CVE-2012-1234MEDIUM
6.5
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to…Feb 21, 2012›
CVE-2024-2453MEDIUM
6.4
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authen…Mar 21, 2024›
CVE-2012-0237MEDIUM
6.4
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing …Feb 21, 2012›
CVE-2025-46268MEDIUM
6.3
Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute ar…Dec 18, 2025›
CVE-2024-39364MEDIUM
6.3
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. Th…Sep 27, 2024›
CVE-2017-14016MEDIUM
6.3
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_201…Nov 6, 2017›
CVE-2021-21803MEDIUM
6.1
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-Se…Jul 16, 2021›
CVE-2021-21802MEDIUM
6.1
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-Se…Jul 16, 2021›
CVE-2021-21801MEDIUM
6.1
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-Se…Jul 16, 2021›
CVE-2021-21800MEDIUM
6.1
Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-S…Jul 16, 2021›
CVE-2021-21799MEDIUM
6.1
Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech …Jul 16, 2021›
CVE-2021-32956MEDIUM
6.1
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an …Jun 18, 2021›
CVE-2021-34540MEDIUM
6.1
Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WAD…Jun 11, 2021›
CVE-2019-18233MEDIUM
6.1
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neu…Mar 17, 2021›
CVE-2018-15703MEDIUM
6.1
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnera…Oct 22, 2018›
CVE-2018-10591MEDIUM
6.1
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2012-1235MEDIUM
6.0
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote au…Feb 21, 2012›
CVE-2012-0235MEDIUM
6.0
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows re…Feb 21, 2012›
CVE-2024-37187MEDIUM
5.7
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 enc…Sep 27, 2024›
CVE-2024-34542MEDIUM
5.7
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device…Sep 27, 2024›
CVE-2020-16211MEDIUM
5.5
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability m…Aug 6, 2020›
CVE-2025-34266MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34265MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34264MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34263MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34262MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34261MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34260MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34259MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34258MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34257MEDIUM
5.4
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vul…Dec 5, 2025›
CVE-2025-34237MEDIUM
5.4
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerab…Nov 6, 2025›
CVE-2025-34236MEDIUM
5.4
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerab…Nov 6, 2025›
CVE-2025-53519MEDIUM
5.4
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a …Jul 11, 2025›
CVE-2025-53397MEDIUM
5.4
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a …Jul 11, 2025›
CVE-2025-41442MEDIUM
5.4
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a …Jul 11, 2025›
CVE-2018-15707MEDIUM
5.4
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp pag…Oct 31, 2018›
CVE-2015-3948MEDIUM
5.4
Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticat…Jan 15, 2016›
CVE-2018-5445MEDIUM
5.3
A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. …Jan 25, 2018›
CVE-2018-5443MEDIUM
5.3
A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. W…Jan 25, 2018›
CVE-2015-3943MEDIUM
5.3
Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about…Jan 15, 2016›
CVE-2016-4528MEDIUM
5.0
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of s…Jun 25, 2016›
CVE-2012-0241MEDIUM
5.0
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory…Feb 21, 2012›
CVE-2012-0239MEDIUM
5.0
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication,…Feb 21, 2012›
CVE-2012-0236MEDIUM
5.0
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information…Feb 21, 2012›
CVE-2016-5810MEDIUM
4.9
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators …May 2, 2017›
CVE-2025-67653MEDIUM
4.3
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to deter…Dec 18, 2025›
CVE-2025-14848MEDIUM
4.3
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker…Dec 18, 2025›
CVE-2025-46704MEDIUM
4.3
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow…Jul 11, 2025›
CVE-2021-38431MEDIUM
4.3
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functi…Oct 15, 2021›
CVE-2012-0233MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote at…Feb 21, 2012›
CVE-2011-4523MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 al…Feb 21, 2012›
CVE-2011-4522MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 a…Feb 21, 2012›