VYPR

Vendor CVEs

Advantech

All CVEs

388 total · sorted by risk
  • CVE-2025-34259MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without…

  • CVE-2025-34258MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without…

  • CVE-2025-34257MedDec 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without…

  • CVE-2025-34237MedNov 6, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…

  • CVE-2025-34236MedNov 6, 2025
    risk 0.35cvss 5.4epss 0.00

    Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…

  • CVE-2025-53519MedJul 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to …

  • CVE-2025-53397MedJul 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information…

  • CVE-2025-41442MedJul 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading…

  • CVE-2021-42703MedNov 15, 2021
    risk 0.35cvss 5.4epss 0.01

    This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.

  • CVE-2021-32951MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS.

  • CVE-2018-5445MedJan 25, 2018
    risk 0.35cvss 5.3epss 0.02

    A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

  • CVE-2018-5443MedJan 25, 2018
    risk 0.35cvss 5.3epss 0.01

    A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.

  • CVE-2015-3948MedJan 15, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-3943MedJan 15, 2016
    risk 0.35cvss 5.3epss 0.02

    Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

  • CVE-2025-48461MedJun 24, 2025
    risk 0.33cvss 5.0epss 0.00

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

  • CVE-2016-4528MedJun 25, 2016
    risk 0.33cvss 5.0epss 0.01

    Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.

  • CVE-2022-2137MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

  • CVE-2021-21923MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21921MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21920MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘surname_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21919MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ord’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site…

  • CVE-2021-21918MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without…

  • CVE-2025-67653MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.01

    Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

  • CVE-2025-14848MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.01

    Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

  • CVE-2025-46704MedJul 11, 2025
    risk 0.28cvss 4.3epss 0.04

    A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or…

  • CVE-2021-38431MedOct 15, 2021
    risk 0.28cvss 4.3epss 0.01

    An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.

  • CVE-2025-48470MedJun 24, 2025
    risk 0.27cvss 4.1epss 0.00

    Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, potentially leading to session hijacking, defacement, credential theft, or privilege escalation.

  • CVE-2025-48462MedJun 24, 2025
    risk 0.27cvss 4.2epss 0.00

    Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block other users from logging in, thereby preventing legitimate users from gaining access to the product.

  • CVE-2025-48463LowJun 24, 2025
    risk 0.20cvss 3.1epss 0.00

    Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses unencrypted HTTP communication, potentially leading to unauthorised access or data tampering.

  • CVE-2014-2364Jul 19, 2014
    risk 0.08cvss epss 0.61

    Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9)…

  • CVE-2011-0340May 4, 2011
    risk 0.06cvss epss 0.32

    Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers…

  • CVE-2014-8387Nov 20, 2014
    risk 0.05cvss epss 0.31

    cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

  • CVE-2014-0763Apr 12, 2014
    risk 0.05cvss epss 0.19

    An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll is exposed through SOAP interfaces, and the exposed functions are vulnerable to SOAP injection. This may allow unexpected SQL action and access to records in…

  • CVE-2014-9208Sep 11, 2015
    risk 0.04cvss epss 0.09

    Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.

  • CVE-2012-0242Feb 21, 2012
    risk 0.04cvss epss 0.07

    Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.

  • CVE-2011-4041Feb 6, 2012
    risk 0.04cvss epss 0.18

    webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.

  • CVE-2014-8386Jan 20, 2015
    risk 0.03cvss epss 0.06

    Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.

  • CVE-2013-2299Aug 22, 2013
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1627Mar 11, 2013
    risk 0.03cvss epss 0.03

    Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.

  • CVE-2012-0241Feb 21, 2012
    risk 0.03cvss epss 0.05

    Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.

  • CVE-2011-0488Jan 18, 2011
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long…

  • CVE-2026-14162CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.

  • CVE-2026-14161HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.

  • CVE-2015-6476Nov 7, 2015
    risk 0.00cvss epss 0.02

    Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.

  • CVE-2014-9202Sep 28, 2015
    risk 0.00cvss epss 0.01

    Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitrary code via a crafted file that triggers long string arguments to functions.

  • CVE-2014-8385Feb 13, 2015
    risk 0.00cvss epss 0.04

    Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2014-8388Nov 21, 2014
    risk 0.00cvss epss 0.01

    Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows remote attackers to execute arbitrary code via a crafted ip_address parameter in an HTML document.

  • CVE-2014-0992Sep 20, 2014
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the password parameter.

  • CVE-2014-0991Sep 20, 2014
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projectname parameter.

  • CVE-2014-0990Sep 20, 2014
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserName parameter.

Page 7 of 8