VYPR
Vendor

Advantech

Products
94
CVEs
388
Across products
580
Status
Private

Products

94
View all 94 products →

Recent CVEs

388
View all 388 CVEs →
  • CVE-2016-0854CriJan 15, 2016
    risk 0.73cvss 9.8epss 0.77

    Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

  • CVE-2022-2143CriJul 22, 2022
    risk 0.71cvss 9.8epss 0.59

    The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2017-16720CriJan 5, 2018
    risk 0.71cvss 9.8epss 0.50

    A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.

  • CVE-2021-22652CriFeb 11, 2021
    risk 0.70cvss 9.8epss 0.37

    Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.

  • CVE-2021-21805CriAug 5, 2021
    risk 0.69cvss 9.8epss 0.70

    An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability.

  • CVE-2025-52694CriJan 12, 2026
    risk 0.68cvss 10.0epss 0.38

    Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability.…

  • CVE-2018-6911CriFeb 13, 2018
    risk 0.68cvss 9.8epss 0.13

    The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).

  • CVE-2017-16716CriJan 5, 2018
    risk 0.67cvss 9.8epss 0.06

    A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

  • CVE-2016-0857CriJan 15, 2016
    risk 0.66cvss 9.8epss 0.28

    Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2023-5642CriOct 18, 2023
    risk 0.65cvss 9.8epss 0.17

    Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information.

  • CVE-2021-38389CriOct 18, 2021
    risk 0.65cvss 9.8epss 0.10

    Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.

  • CVE-2021-38408CriSep 9, 2021
    risk 0.65cvss 9.8epss 0.12

    A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

  • CVE-2021-22658CriFeb 11, 2021
    risk 0.65cvss 9.8epss 0.13

    Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.

  • CVE-2019-10993CriJun 28, 2019
    risk 0.65cvss 9.8epss 0.11

    In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code.

  • CVE-2016-0856CriJan 15, 2016
    risk 0.65cvss 9.8epss 0.17

    Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2025-34256CriDec 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email…

  • CVE-2022-50593CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.01

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the…

  • CVE-2022-50591CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.01

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the…

  • CVE-2024-50375CriNov 26, 2024
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated…

  • CVE-2024-50374CriNov 26, 2024
    risk 0.64cvss 9.8epss 0.01

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability…