CVE-2026-79697
moderateCommand Injection in Advantech WISE-6610 Gateway Basic Station Certificate Handler
CVE-2026-79697 is a command injection flaw (CWE-74/CWE-77) in the basicstation_apply function of the Basic Station Certificate-Deletion Handler in Advantech WISE-6610 series industrial gateways running firmware 1.2.1_20251110. A remote attacker who can reach the gateway's management interface sends a manipulated 'act' argument to the certificate-deletion handler, causing arbitrary commands to be injected and executed on the device. The CVSS 4.0 score of 8.6 assumes only low privileges are required and rates confidentiality, integrity and availability impact as high, so successful exploitation effectively means full compromise of the gateway. Any organization running one of the thirteen affected WISE-6610/WISE-6610P models is affected, especially where the gateway's management interface is reachable from untrusted networks. The advisory states the exploit has been publicly disclosed (EPSS 3.4%, 88th percentile), though the flaw is not yet in CISA KEV and no standalone PoC is catalogued; the vendor responded quickly and shipped a fix in firmware 1.2.4_20260821.
What to do: Upgrade all thirteen affected WISE-6610/WISE-6610P models to firmware 1.2.4_20260821 or later. Until patching is complete, restrict access to the gateways' management interfaces to trusted management networks, review which accounts hold the low-privilege credentials the attack requires, and inventory any gateways exposed at remote or internet-facing sites. Monitor vendor advisories, as exploitation activity may follow the publicly disclosed exploit.
| Advantech WISE-6610-NB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-EB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-TB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-JB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-CB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-EL-NB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-EL-EB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-EL-TB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-EL-JB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610-EL-CB | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610P-DEA | 1.2.1_20251110; fixed in 1.2.4_20260821 |
| Advantech WISE-6610P-DNA | 1.2.1_20251110; fixed in 1.2.4_20260821 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.