VYPR

Vendor CVEs

Advantech

All CVEs

405 total · sorted by risk
  • CVE-2026-73173HigSep 16, 2026
    risk 0.57cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management…

  • CVE-2025-14849HigDec 18, 2025
    risk 0.57cvss 8.8epss 0.01

    Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2025-62630HigNov 6, 2025
    risk 0.57cvss 8.8epss 0.01

    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

  • CVE-2025-58423HigNov 6, 2025
    risk 0.57cvss 8.8epss 0.01

    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

  • CVE-2025-53515HigJul 11, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not sanitized, allowing an …

  • CVE-2025-52577HigJul 11, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not properly…

  • CVE-2024-38308HigSep 27, 2024
    risk 0.57cvss 8.8epss 0.00

    Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.

  • CVE-2023-3256HigJun 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

  • CVE-2021-40396HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-40389HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-40388HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21936HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘health_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21917HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done…

  • CVE-2021-21916HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This…

  • CVE-2021-21915HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This…

  • CVE-2021-22669HigApr 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges…

  • CVE-2020-25161HigFeb 23, 2021
    risk 0.57cvss 8.8epss 0.02

    The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

  • CVE-2020-13555HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM…

  • CVE-2020-13553HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to…

  • CVE-2020-13552HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or…

  • CVE-2020-13551HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.00

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM…

  • CVE-2020-12026HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

  • CVE-2020-10603HigApr 9, 2020
    risk 0.57cvss 8.8epss 0.01

    WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.

  • CVE-2020-10607HigMar 27, 2020
    risk 0.57cvss 8.8epss 0.02

    In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

  • CVE-2019-13556HigSep 18, 2019
    risk 0.57cvss 8.8epss 0.02

    In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.

  • CVE-2019-13552HigSep 18, 2019
    risk 0.57cvss 8.8epss 0.03

    In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution.

  • CVE-2017-12704HigAug 30, 2017
    risk 0.57cvss 8.8epss 0.02

    A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to the heap-based…

  • CVE-2017-12702HigAug 30, 2017
    risk 0.57cvss 8.8epss 0.02

    An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an attacker to execute arbitrary code.

  • CVE-2015-3946HigJan 15, 2016
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2026-73177HigSep 16, 2026
    risk 0.56cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management…

  • CVE-2026-73176HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker…

  • CVE-2026-73171HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem…

  • CVE-2026-73170HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on…

  • CVE-2026-73167HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker…

  • CVE-2026-73166HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the…

  • CVE-2026-73165HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker…

  • CVE-2026-73164HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker…

  • CVE-2026-73163HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker…

  • CVE-2026-19535HigSep 16, 2026
    risk 0.56cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing…

  • CVE-2019-6521HigFeb 5, 2019
    risk 0.56cvss 8.6epss 0.02

    WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and manipulate sensitive information.

  • CVE-2022-2138HigJul 22, 2022
    risk 0.54cvss 8.2epss 0.11

    The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition.

  • CVE-2025-14850HigDec 18, 2025
    risk 0.53cvss 8.1epss 0.01

    Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

  • CVE-2025-48466HigJun 24, 2025
    risk 0.53cvss 8.1epss 0.01

    Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.

  • CVE-2022-2142HigJul 22, 2022
    risk 0.53cvss 8.1epss 0.01

    The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information.

  • CVE-2016-0858HigJan 15, 2016
    risk 0.53cvss 8.1epss 0.05

    Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.

  • CVE-2015-6467HigJan 15, 2016
    risk 0.53cvss 8.1epss 0.04

    Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.

  • CVE-2015-3947HigJan 15, 2016
    risk 0.53cvss 8.1epss 0.02

    SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2024-39275HigSep 27, 2024
    risk 0.52cvss 8.0epss 0.00

    Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the…

  • CVE-2024-28948HigSep 27, 2024
    risk 0.52cvss 8.0epss 0.00

    Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.

  • CVE-2016-9349HigFeb 13, 2017
    risk 0.52cvss 7.5epss 0.06

    An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.

Page 3 of 9