Advantech Vulnerabilities and Affected Products
Vulnerabilities associated with WebAccess/SCADA.
Products
Clear product- WebAccess31 vulnerabilities
- EKI-6333AC-1GPO20 vulnerabilities
- EKI-6333AC-2G20 vulnerabilities
- EKI-6333AC-2GD20 vulnerabilities
- eki-6333ac-1gpo_firmware19 vulnerabilities
- eki-6333ac-2g_firmware19 vulnerabilities
- eki-6333ac-2gd_firmware19 vulnerabilities
- iView17 vulnerabilities
- WebAccess/SCADA16 vulnerabilities
- WebAccess/VPN12 vulnerabilities
- Advantech WebAccess9 vulnerabilities
- Advantech Wireless Sensing and Equipment (WISE)8 vulnerabilities
- R-SeeNet8 vulnerabilities
- EKI-15215 vulnerabilities
- EKI-15225 vulnerabilities
- EKI-15245 vulnerabilities
- ADAM-56304 vulnerabilities
- DeviceOn/iEdge4 vulnerabilities
- ADAM 55502 vulnerabilities
- adam-5630_firmware2 vulnerabilities
- HMI Designer2 vulnerabilities
- ADAM-36001 vulnerability
- ECOWatch SaaS-Composer1 vulnerability
- Hospital Quering Management1 vulnerability
- Hospital Queuing Management1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-6888HIGH | Generated title:Advantech SQL Injection VulnerabilitySuccessful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database. CWE-89May 13, 2026 | CVSS7.2v3.1 | EPSS0.375% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67653MEDIUM | Advantech WebAccess/SCADA Path TraversalAdvantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files. CWE-22Dec 18, 2025 | CVSS5.3v4.0 | EPSS0.647% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-46268MEDIUM | Advantech WebAccess/SCADA SQL InjectionAdvantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands. CWE-89Dec 18, 2025 | CVSS5.3v4.0 | EPSS0.297% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14848MEDIUM | Advantech WebAccess/SCADA Absolute Path TraversalAdvantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files. CWE-36Dec 18, 2025 | CVSS5.3v4.0 | EPSS0.592% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14849HIGH | Advantech WebAccess/SCADA Unrestricted Upload of File with Dangerous TypeAdvantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. CWE-434Dec 18, 2025 | CVSS8.7v4.0 | EPSS0.553% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14850HIGH | Advantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted DirectoryAdvantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files. CWE-22Dec 18, 2025 | CVSS7.2v4.0 | EPSS0.839% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2453MEDIUM | Advantech WebAccess/SCADA SQL InjectionThere is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database. CWE-89Mar 21, 2024 | CVSS6.4v3.1 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1437CRITICAL | CVE-2023-1437All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files. | CVSS9.8v3.1 | EPSS2.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2866HIGH | Advantech WebAccess Insufficient Type DistinctionIf an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server. | CVSS7.3v3.1 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22450HIGH | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution. CWE-434Jun 5, 2023 | CVSS7.2v3.1 | EPSS0.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-32540HIGH | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution. CWE-94Jun 5, 2023 | CVSS7.2v3.1 | EPSS0.898% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-32628HIGH | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution. CWE-434Jun 5, 2023 | CVSS7.2v3.1 | EPSS0.713% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-3975CRITICAL | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCTL 70603 RPC message. | CVSS9.8v3.1 | EPSS4.57% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-6554HIGH | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition. CWE-284Apr 5, 2019 | CVSS7.5v3.1 | EPSS1.57% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-6550CRITICAL | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a lack of proper validation of the length of user-supplied data, may allow remote code execution. | CVSS9.8v3.1 | EPSS6.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-6552CRITICAL | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution. | CVSS9.8v3.1 | EPSS3.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |