Vulnerabilities
317 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-52694 | Unauthenticated SQL Injection in Advantech IoT Edge and IoTSuite Platforms CVE-2025-52694 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) affecting multiple Advantech industrial IoT platform products, including IoT Edge (Linux Docker and Windows) and IoTSuite (Growth/Starter Linux Docker and SaaS Composer). An unauthenticated remote attacker can send crafted input to an internet-exposed vulnerable service, where it is processed as SQL commands. Successful exploitation could compromise the confidentiality, integrity, and availability of data handled by the service, potentially enabling data theft, modification, or denial of service. Users and administrators running affected versions of these Advantech products—especially with the service reachable from the Internet—are affected and are advised to update immediately. There is no confirmed in-the-wild exploitation, no public proof-of-concept, and the flaw is not yet in CISA KEV, but an EPSS score of 40.4% (99th percentile) indicates a high probability of exploitation within the next 30 days. Do: Immediately update all affected Advantech IoT Edge and IoTSuite components to the latest versions per Advantech's advisory, as specific fixed version numbers are not provided in the available data. Until patched, restrict Internet-facing exposure of these services via firewall rules or a reverse proxy/WAF, and review service logs for anomalous SQL activity or unauthenticated requests. After patching, verify that the service is no longer reachable directly from the Internet. | 9.8 | 40% |
| nicheunknown (no public install-base or internet-exposure scan data for these products) | ||
| CVE-2025-14849 | Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2025-34256 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-63701 | A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size matches the input buffer size, leading to invalid memory operations and heap corruption. This vulnerability can cause denial of service through application crashes and potentially lead to code execution in user space. Local access is required to exploit this vulnerability. NVD description · AI analysis pending | 6.8 | <1% | PoC |
| — | |
| CVE-2025-59171 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with s Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2025-34239 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authentic Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename. NVD description · AI analysis pending | 8.6 group max | 2% |
| — | ||
| CVE-2022-50593 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authenti Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges. NVD description · AI analysis pending | 9.3 group max | <1% |
| — | ||
| CVE-2025-53475 | A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account. NVD description · AI analysis pending | 8.7 group max | 6% |
| — | ||
| CVE-2025-48470 | Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, potentially leading to session hijacking, defacement, credential theft, or privilege escalation. NVD description · AI analysis pending | 4.1 | <1% |
| — | ||
| CVE-2025-48469 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to bac Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation. NVD description · AI analysis pending | 9.6 | <1% | PoC |
| — |