VYPR

Vendor CVEs

Advantech

All CVEs

388 total · sorted by risk
  • CVE-2025-52459MedJul 11, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command without proper …

  • CVE-2025-48468MedJun 24, 2025
    risk 0.42cvss 6.4epss 0.00

    Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.

  • CVE-2025-48467MedJun 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and system unavailability.

  • CVE-2024-50377MedNov 26, 2024
    risk 0.42cvss 6.5epss 0.00

    A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability is associated to the backup configuration functionality…

  • CVE-2024-2453MedMar 21, 2024
    risk 0.42cvss 6.4epss 0.00

    There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

  • CVE-2023-4215MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.00

    Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.

  • CVE-2021-21937MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21935MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter2’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21934MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘imei_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21933MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘esn_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21932MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘name_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21931MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21930MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21929MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21928MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21927MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘loc_filter’ parameter.

  • CVE-2021-21926MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘health_filter’ parameter.

  • CVE-2021-21925MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘firm_filter’ parameter.

  • CVE-2021-21922MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘username_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-22674MedAug 10, 2021
    risk 0.42cvss 6.5epss 0.01

    The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

  • CVE-2021-32954MedJun 18, 2021
    risk 0.42cvss 6.5epss 0.02

    Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.

  • CVE-2020-10623MedApr 9, 2020
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.

  • CVE-2019-18229MedOct 31, 2019
    risk 0.42cvss 6.5epss 0.02

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.

  • CVE-2017-16732MedJan 12, 2018
    risk 0.42cvss 6.5epss 0.01

    A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated attacker to specify an arbitrary address.

  • CVE-2025-46268MedDec 18, 2025
    risk 0.41cvss 6.3epss 0.00

    Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

  • CVE-2024-39364MedSep 27, 2024
    risk 0.41cvss 6.3epss 0.00

    Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by…

  • CVE-2021-21800MedJul 16, 2021
    risk 0.41cvss 6.1epss 0.14

    Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An…

  • CVE-2021-21799MedJul 16, 2021
    risk 0.41cvss 6.1epss 0.12

    Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An…

  • CVE-2026-36226MedMay 22, 2026
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component

  • CVE-2021-22676MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the…

  • CVE-2021-21803MedJul 16, 2021
    risk 0.40cvss 6.1epss 0.08

    This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

  • CVE-2021-21802MedJul 16, 2021
    risk 0.40cvss 6.1epss 0.10

    This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

  • CVE-2021-32956MedJun 18, 2021
    risk 0.40cvss 6.1epss 0.01

    Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.

  • CVE-2021-34540MedJun 11, 2021
    risk 0.40cvss 6.1epss 0.01

    Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.

  • CVE-2021-27436MedMar 18, 2021
    risk 0.40cvss 6.1epss 0.01

    WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage…

  • CVE-2019-18233MedMar 17, 2021
    risk 0.40cvss 6.1epss 0.01

    In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.

  • CVE-2018-15703MedOct 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is…

  • CVE-2018-10591MedMay 15, 2018
    risk 0.40cvss 6.1epss 0.01

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been…

  • CVE-2018-15707MedOct 31, 2018
    risk 0.38cvss 5.4epss 0.02

    Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

  • CVE-2024-37187MedSep 27, 2024
    risk 0.37cvss 5.7epss 0.00

    Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

  • CVE-2024-34542MedSep 27, 2024
    risk 0.37cvss 5.7epss 0.00

    Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

  • CVE-2020-16211MedAug 6, 2020
    risk 0.36cvss 5.5epss 0.01

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

  • CVE-2016-5810MedMay 2, 2017
    risk 0.36cvss 4.9epss 0.15

    upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

  • CVE-2025-34266MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin…

  • CVE-2025-34265MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later…

  • CVE-2025-34264MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in…

  • CVE-2025-34263MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin…

  • CVE-2025-34262MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or…

  • CVE-2025-34261MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group…

  • CVE-2025-34260MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule…

Page 6 of 8