CVE-2026-79698
nicheRemote Command Injection in Advantech WISE-6610 Node-RED Library
CVE-2026-79698 is a remote command injection flaw in the nodered_lib_apply function of the Node-RED Library component in Advantech WISE-6610-series industrial routers running firmware 1.2.1_20251110. An attacker with network access to the device and at least low-level privileges can manipulate the "act" argument to inject and execute operating-system commands on the router. The vulnerability carries high impact ratings for confidentiality, integrity, and availability, so successful exploitation effectively gives an attacker full control of the device, which can serve as a foothold in industrial networks. All WISE-6610, WISE-6610-EL, and WISE-6610P variants on affected firmware are exposed, with remotely attackable deployments being those whose web/Node-RED interface reaches untrusted networks. A public exploit is available and exploitation is considered plausible (EPSS 1.7%, 76th percentile), but the flaw is not yet in CISA's KEV catalog and there are no confirmed in-the-wild incident reports.
What to do: Upgrade affected WISE-6610, WISE-6610-EL, and WISE-6610P routers to firmware 1.2.4_20260821 as soon as possible, since the vendor released this fixed version promptly after being notified. Operators running older builds (including 1.2.1_20251110) who cannot upgrade immediately should restrict access to the device's web/Node-RED management interface to trusted networks and review devices for signs of unexpected command execution.
| Advantech WISE-6610-NB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-EB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-TB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-JB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-CB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-EL-NB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-EL-EB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-EL-TB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-EL-JB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610-EL-CB | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610P-DEA | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
| Advantech WISE-6610P-DNA | 1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.