advantech

385 tracked vulnerabilities.

CVE-2025-58423 HIGH
Advantech DeviceOn iEdge <= 2.0.2 - Directory Traversal and DoS
Nov 06, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-34247 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via NetworksController Datatable Search
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34246 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AjaxPrevalidationController
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34245 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via Datatable Search Parameters
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34244 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via Datatable Search Parameters
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34243 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via Datatable Search Parameters
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34242 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AjaxNetworkController Datatable Search
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34241 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AjaxDeviceController.ajaxDeviceAction
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34240 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated SQL Injection via AppManagementController.appUpgradeAction
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34239 HIGH
Advantech WebAccess/VPN < 1.1.5 - Authenticated OS Command Injection via AppManagementController.appUpgradeAction()
Nov 06, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-34238 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Authenticated Path Traversal via AjaxStandaloneVpnClientsController
Nov 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34237 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Stored Cross-Site Scripting via StandaloneVpnClientsController
Nov 06, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34236 MEDIUM
Advantech WebAccess/VPN < 1.1.5 - Stored Cross-Site Scripting via NetworksController.addNetworkAction()
Nov 06, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-53519 MEDIUM
Advantech iView <5.7.05 build 7057 - XSS
Jul 11, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-53515 HIGH
Advantech iView - SQL Injection, RCE
Jul 11, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-53509 MEDIUM
Advantech iView - Command Injection
Jul 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-53475 HIGH
Advantech iView - SQL Injection, RCE
Jul 11, 2025
CVSS 8.8
EPSS 0.02
CVE-2025-53397 MEDIUM
Advantech iView <5.7.05 build 7057 - XSS
Jul 11, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-52577 HIGH
Advantech iView < 5.7.05.7057 - SQLi & RCE via NetworkServlet.archiveTrapRange()
Jul 11, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-52459 MEDIUM
Advantech iView - Command Injection
Jul 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-48891 HIGH
Advantech iView < 5.7.05.7057 - Authenticated SQL Injection via CUtils.checkSQLInjection()
Jul 11, 2025
CVSS 7.6
EPSS 0.00
CVE-2025-46704 MEDIUM
Advantech iView < 5.7.05.7057 - Authenticated Path Traversal via NetworkServlet.processImportRequest()
Jul 11, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-41442 MEDIUM
Advantech iView < 5.7.05.7057 - Reflected Cross-Site Scripting via Input Parameter Manipulation
Jul 11, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-48470 MEDIUM
Advantech WISE-4000 Series LAN Firmware - Stored Cross-Site Scripting
Jun 24, 2025
CVSS 4.1
EPSS 0.00
CVE-2025-48469 CRITICAL
Advantech WISE-4000 LAN Firmware Update - Unauthenticated Firmware Upload
Jun 24, 2025
CVSS 9.6
EPSS 0.00