ZeroHour

CVE-2026-79698

niche

Remote Command Injection in Advantech WISE-6610 Node-RED Library

CVSS 4.0
8.6 high
EPSS
2%p76
Published
()
Modified
AI analysis

CVE-2026-79698 is a remote command injection flaw in the nodered_lib_apply function of the Node-RED Library component in Advantech WISE-6610-series industrial routers running firmware 1.2.1_20251110. An attacker with network access to the device and at least low-level privileges can manipulate the "act" argument to inject and execute operating-system commands on the router. The vulnerability carries high impact ratings for confidentiality, integrity, and availability, so successful exploitation effectively gives an attacker full control of the device, which can serve as a foothold in industrial networks. All WISE-6610, WISE-6610-EL, and WISE-6610P variants on affected firmware are exposed, with remotely attackable deployments being those whose web/Node-RED interface reaches untrusted networks. A public exploit is available and exploitation is considered plausible (EPSS 1.7%, 76th percentile), but the flaw is not yet in CISA's KEV catalog and there are no confirmed in-the-wild incident reports.

What to do: Upgrade affected WISE-6610, WISE-6610-EL, and WISE-6610P routers to firmware 1.2.4_20260821 as soon as possible, since the vendor released this fixed version promptly after being notified. Operators running older builds (including 1.2.1_20251110) who cannot upgrade immediately should restrict access to the device's web/Node-RED management interface to trusted networks and review devices for signs of unexpected command execution.

Affected
Advantech WISE-6610-NB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-EB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-TB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-JB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-CB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-EL-NB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-EL-EB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-EL-TB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-EL-JB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610-EL-CB1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610P-DEA1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Advantech WISE-6610P-DNA1.2.1_20251110 (confirmed affected; fixed in 1.2.4_20260821)
Estimated exposure
nichelikely thousands to tens of thousands of deployed units worldwide — The WISE-6610 series is a niche line of industrial cellular routers/gateways typically deployed in bounded industrial IoT installations rather than at mass consumer scale, and no public install counts or internet-exposure scan data are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.