VYPR

Deviceon\/iedge

by Advantech

CVEs (5)

  • CVE-2025-62630HigNov 6, 2025
    risk 0.57cvss 8.8epss 0.01

    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

  • CVE-2025-58423HigNov 6, 2025
    risk 0.57cvss 8.8epss 0.01

    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

  • CVE-2021-40389HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-59171HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.01

    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

  • CVE-2025-64302MedNov 6, 2025
    risk 0.42cvss 6.4epss 0.00

    Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.