Vulnerabilities in Advantech

161 results
Vexday analysis

Com 142 CVEs catalogadas, o portfólio da Advantech apresenta 21 vulnerabilidades de severidade crítica e 4 com prova de conceito pública disponível, o que representa superfície de ataque concreta para agentes com capacidade de exploração. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, embora esse dado não elimine o risco, especialmente considerando que CVE-2014-2364 — a vulnerabilidade de maior destaque ativo — registra escore EPSS de 0,6138, indicando probabilidade relevante de exploração. A falha mais recorrente por tipo é CWE-89 (injeção de SQL), uma classe de vulnerabilidade bem documentada e com técnicas de exploração amplamente conhecidas, o que reforça a necessidade de atenção redobrada em ambientes que dependem de componentes Advantech expostos a redes. Equipes de segurança devem priorizar a revisão das vulnerabilidades críticas com PoC pública, particularmente em instalações de tecnologia operacional onde a janela de correção tende a ser mais restrita.

CVE-2026-73163HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 0.9%CVE-2026-73164HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 0.9%CVE-2023-32540HIGH In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwritEPSS 0.9%CVE-2018-15703Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacEPSS 0.9%CVE-2023-22450HIGH In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an AEPSS 0.8%CVE-2025-67653MEDIUMAdvantech WebAccess/SCADA Path TraversalEPSS 0.7%CVE-2023-32628HIGH In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify thEPSS 0.7%CVE-2025-59171HIGHAdvantech DeviceOn/iEdge Path TraversalEPSS 0.7%CVE-2021-38431MEDIUMAdvantech WebAccess SCADAEPSS 0.7%CVE-2024-50361HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 0.7%CVE-2022-50593CRITICALAdvantech iView < v5.7.04 Build 6425 search_term Parameter SQL Injection RCEEPSS 0.7%CVE-2026-73173HIGHNozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol oEPSS 0.7%CVE-2025-62630HIGHAdvantech DeviceOn/iEdge Path TraversalEPSS 0.7%CVE-2026-73166HIGHNozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management inteEPSS 0.7%CVE-2023-2611CRITICALAdvantech R-SeeNet Use of Hard-coded CredentialsEPSS 0.7%CVE-2025-14848MEDIUMAdvantech WebAccess/SCADA Absolute Path TraversalEPSS 0.7%CVE-2023-3256HIGHAdvantech R-SeeNet External Control of File Name or PathEPSS 0.6%CVE-2021-42703MEDIUMAzeoTech DAQFactoryEPSS 0.6%CVE-2022-50592CRITICALAdvantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCEEPSS 0.6%CVE-2026-14162CRITICALAdvantech|Hospital Quering Management - Missing AuthenticationEPSS 0.6%