Advantech WISE-6610-NB Background Management openvpn_apply os command injection
26Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.6epss 13%
probabilidad de explotación
13%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Productos afectados
Advantech · WISE-6610-CBAdvantech · WISE-6610-EBAdvantech · WISE-6610-EL-CBAdvantech · WISE-6610-EL-EBAdvantech · WISE-6610-EL-JBAdvantech · WISE-6610-EL-NBAdvantech · WISE-6610-EL-TBAdvantech · WISE-6610-JBAdvantech · WISE-6610-NBAdvantech · WISE-6610P-DEAAdvantech · WISE-6610P-DNAAdvantech · WISE-6610P-DTAAdvantech · WISE-6610-TBReferencias
https://github.com/master-abc/cve/issues/37https://vuldb.com/cve/CVE-2026-2670https://vuldb.com/submit/753293https://vuldb.com/vuln/346467https://vuldb.com/vuln/346467/ctihttps://www.advantech.com/https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRIhttps://www.advantech.com/zh-tw/security-advisory