ZeroHour

Vulnerabilities

317 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-52694
Unauthenticated SQL Injection in Advantech IoT Edge and IoTSuite Platforms

CVE-2025-52694 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) affecting multiple Advantech industrial IoT platform products, including IoT Edge (Linux Docker and Windows) and IoTSuite (Growth/Starter Linux Docker and SaaS Composer). An unauthenticated remote attacker can send crafted input to an internet-exposed vulnerable service, where it is processed as SQL commands. Successful exploitation could compromise the confidentiality, integrity, and availability of data handled by the service, potentially enabling data theft, modification, or denial of service. Users and administrators running affected versions of these Advantech products—especially with the service reachable from the Internet—are affected and are advised to update immediately. There is no confirmed in-the-wild exploitation, no public proof-of-concept, and the flaw is not yet in CISA KEV, but an EPSS score of 40.4% (99th percentile) indicates a high probability of exploitation within the next 30 days.

Do: Immediately update all affected Advantech IoT Edge and IoTSuite components to the latest versions per Advantech's advisory, as specific fixed version numbers are not provided in the available data. Until patched, restrict Internet-facing exposure of these services via firewall rules or a reverse proxy/WAF, and review service logs for anomalous SQL activity or unauthenticated requests. After patching, verify that the service is no longer reachable directly from the Internet.

9.840%
  • Advantech IoT Edge (Linux Docker)
  • Advantech IoT Edge (Windows)
  • Advantech IoTSuite Growth (Linux Docker)
  • +2 more
nicheunknown (no public install-base or internet-exposure scan data for these products)
CVE-2025-14849
+4 in the same advisory: …14850 …67653 …14848 …46268
Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

NVD description · AI analysis pending
8.7
group max
<1%
  • advantech webaccess\/scada
CVE-2025-34256
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability.

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.

NVD description · AI analysis pending
10.0
group max
<1%
  • advantech wise-deviceon server
CVE-2025-63701
A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size matches the input buffer size, leading to invalid memory operations and heap corruption. This vulnerability can cause denial of service through application crashes and potentially lead to code execution in user space. Local access is required to exploit this vulnerability.

NVD description · AI analysis pending
6.8<1% PoC
  • advantech tp 3250 firmware
CVE-2025-59171
+3 in the same advisory: …62630 …58423 …64302
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with s

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

NVD description · AI analysis pending
8.7
group max
<1%
  • advantech deviceon\/iedge
CVE-2025-34239
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authentic

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.

NVD description · AI analysis pending
8.6
group max
2%
  • advantech webaccess\/vpn
CVE-2022-50593
+4 in the same advisory: …50595 …50592 …50591 …50594
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authenti

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

NVD description · AI analysis pending
9.3
group max
<1%
  • advantech iview
CVE-2025-53475
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage().

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.

NVD description · AI analysis pending
8.7
group max
6%
  • advantech iview
CVE-2025-48470
Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in

Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, potentially leading to session hijacking, defacement, credential theft, or privilege escalation.

NVD description · AI analysis pending
4.1<1%
  • advantech wise-4010lan firmware
  • advantech wise-4050lan firmware
  • advantech wise-4060lan firmware
CVE-2025-48469
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to bac

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.

NVD description · AI analysis pending
9.6<1% PoC
  • advantech wise-4060lan firmware
  • advantech wise-4050lan firmware
  • advantech wise-4010lan firmware