CVE-2025-48469

CRITICAL

Advantech WISE-4000 LAN Firmware Update - Unauthenticated Firmware Upload

Title source: manual
STIX 2.1

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://jro.sg/CVEs/CVE-2025-48469/

Scores

CVSS v3 9.6
EPSS 0.0020
EPSS Percentile 41.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (3)
advantech/wise-4010lan_firmware
advantech/wise-4050lan_firmware
advantech/wise-4060lan_firmware
Published Jun 24, 2025
Tracked Since Feb 18, 2026