advantech
385 tracked vulnerabilities.
CVE-2025-58423
HIGH
Advantech DeviceOn iEdge <= 2.0.2 - Directory Traversal and DoS
Nov 06, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-34247
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via NetworksController Datatable Search
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34246
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AjaxPrevalidationController
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34245
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via Datatable Search Parameters
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34244
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via Datatable Search Parameters
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34243
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via Datatable Search Parameters
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34242
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AjaxNetworkController Datatable Search
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34241
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AjaxDeviceController.ajaxDeviceAction
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34240
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AppManagementController.appUpgradeAction
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34239
HIGH
Advantech WebAccess/VPN < 1.1.5 - Authenticated OS Command Injection via AppManagementController.appUpgradeAction()
Nov 06, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-34238
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated Path Traversal via AjaxStandaloneVpnClientsController
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34237
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Stored Cross-Site Scripting via StandaloneVpnClientsController
Nov 06, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34236
MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Stored Cross-Site Scripting via NetworksController.addNetworkAction()
Nov 06, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-53519
MEDIUM
Advantech iView <5.7.05 build 7057 - XSS
Jul 11, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-53515
HIGH
Advantech iView - SQL Injection, RCE
Jul 11, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-53509
MEDIUM
Advantech iView - Command Injection
Jul 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-53475
HIGH
Advantech iView - SQL Injection, RCE
Jul 11, 2025
CVSS 8.8
EPSS 0.02
CVE-2025-53397
MEDIUM
Advantech iView <5.7.05 build 7057 - XSS
Jul 11, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-52577
HIGH
Advantech iView < 5.7.05.7057 - SQLi & RCE via NetworkServlet.archiveTrapRange()
Jul 11, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-52459
MEDIUM
Advantech iView - Command Injection
Jul 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-48891
HIGH
Advantech iView < 5.7.05.7057 - Authenticated SQL Injection via CUtils.checkSQLInjection()
Jul 11, 2025
CVSS 7.6
EPSS 0.00
CVE-2025-46704
MEDIUM
Advantech iView < 5.7.05.7057 - Authenticated Path Traversal via NetworkServlet.processImportRequest()
Jul 11, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-41442
MEDIUM
Advantech iView < 5.7.05.7057 - Reflected Cross-Site Scripting via Input Parameter Manipulation
Jul 11, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-48470
MEDIUM
Advantech WISE-4000 Series LAN Firmware - Stored Cross-Site Scripting
Jun 24, 2025
CVSS 4.1
EPSS 0.00
CVE-2025-48469
CRITICAL
Advantech WISE-4000 LAN Firmware Update - Unauthenticated Firmware Upload
Jun 24, 2025
CVSS 9.6
EPSS 0.00
Products
webaccess 103
advantech_webaccess 44
r-seenet 40
iview 37
webaccess\/scada 29
eki-6333ac-1gpo_firmware 20
eki-6333ac-2g_firmware 20
eki-6333ac-2gd_firmware 20
webaccess\/nms 20
WebAccess 15
webaccess\/hmi_designer 12
webaccess\/vpn 12
webaccess_scada 12
webaccess_dashboard 11
wise-deviceon_server 11
wise-4010lan_firmware 8
wise-4050lan_firmware 8
wise-4060lan_firmware 8
webaccess_hmi_designer 6
deviceon\/iedge 5
eki-1521_firmware 5
eki-1522_firmware 5
eki-1524_firmware 5
wise-paas\/rmm 5
adam-5630_firmware 3
advantech_studio 3
spectre_rt_ert351_firmware 3
susiaccess 3
WebAccess/SCADA 2
eki-1321_series_firmware 2
Quick Filters