VYPR

Vendor CVEs

Advantech

All CVEs

405 total · sorted by risk
  • CVE-2021-34540MedJun 11, 2021
    risk 0.40cvss 6.1epss 0.01

    Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.

  • CVE-2021-27436MedMar 18, 2021
    risk 0.40cvss 6.1epss 0.01

    WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage…

  • CVE-2019-18233MedMar 17, 2021
    risk 0.40cvss 6.1epss 0.01

    In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.

  • CVE-2018-15703MedOct 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is…

  • CVE-2018-10591MedMay 15, 2018
    risk 0.40cvss 6.1epss 0.01

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been…

  • CVE-2018-15707MedOct 31, 2018
    risk 0.38cvss 5.4epss 0.03

    Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

  • CVE-2024-37187MedSep 27, 2024
    risk 0.37cvss 5.7epss 0.00

    Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

  • CVE-2024-34542MedSep 27, 2024
    risk 0.37cvss 5.7epss 0.00

    Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

  • CVE-2020-16211MedAug 6, 2020
    risk 0.36cvss 5.5epss 0.01

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

  • CVE-2016-5810MedMay 2, 2017
    risk 0.36cvss 4.9epss 0.14

    upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

  • CVE-2025-34266MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin…

  • CVE-2025-34265MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later…

  • CVE-2025-34264MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in…

  • CVE-2025-34263MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin…

  • CVE-2025-34262MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or…

  • CVE-2025-34261MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group…

  • CVE-2025-34260MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule…

  • CVE-2025-34259MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without…

  • CVE-2025-34258MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without…

  • CVE-2025-34257MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without…

  • CVE-2025-34237MedNov 6, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…

  • CVE-2025-34236MedNov 6, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…

  • CVE-2025-53519MedJul 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to …

  • CVE-2025-53397MedJul 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information…

  • CVE-2025-41442MedJul 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading…

  • CVE-2021-42703MedNov 15, 2021
    risk 0.35cvss 5.4epss 0.01

    This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.

  • CVE-2021-32951MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS.

  • CVE-2018-5445MedJan 25, 2018
    risk 0.35cvss 5.3epss 0.02

    A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

  • CVE-2018-5443MedJan 25, 2018
    risk 0.35cvss 5.3epss 0.01

    A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.

  • CVE-2015-3948MedJan 15, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-3943MedJan 15, 2016
    risk 0.35cvss 5.3epss 0.02

    Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

  • CVE-2025-48461MedJun 24, 2025
    risk 0.33cvss 5.0epss 0.00

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

  • CVE-2016-4528MedJun 25, 2016
    risk 0.33cvss 5.0epss 0.01

    Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.

  • CVE-2022-2137MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

  • CVE-2021-21923MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21921MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21920MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘surname_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21919MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ord’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site…

  • CVE-2021-21918MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without…

  • CVE-2025-67653MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.01

    Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

  • CVE-2025-14848MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.01

    Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

  • CVE-2025-46704MedJul 11, 2025
    risk 0.28cvss 4.3epss 0.04

    A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or…

  • CVE-2021-38431MedOct 15, 2021
    risk 0.28cvss 4.3epss 0.01

    An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.

  • CVE-2025-48470MedJun 24, 2025
    risk 0.27cvss 4.1epss 0.00

    Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, potentially leading to session hijacking, defacement, credential theft, or privilege escalation.

  • CVE-2025-48462MedJun 24, 2025
    risk 0.27cvss 4.2epss 0.00

    Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block other users from logging in, thereby preventing legitimate users from gaining access to the product.

  • CVE-2025-48463LowJun 24, 2025
    risk 0.20cvss 3.1epss 0.00

    Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses unencrypted HTTP communication, potentially leading to unauthorised access or data tampering.

  • CVE-2014-2364Jul 19, 2014
    risk 0.08cvss —epss 0.61

    Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9)…

  • CVE-2011-0340May 4, 2011
    risk 0.06cvss —epss 0.32

    Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers…

  • CVE-2014-8387Nov 20, 2014
    risk 0.05cvss —epss 0.31

    cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

  • CVE-2014-0763Apr 12, 2014
    risk 0.05cvss —epss 0.19

    An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll is exposed through SOAP interfaces, and the exposed functions are vulnerable to SOAP injection. This may allow unexpected SQL action and access to records in…

Page 7 of 9