CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “advantech”

284 vulnerabilities found for “advantech”

Page 1 of 15

CVE-2025-52694
CRITICAL10.0

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

advantech / iot_edge_linux_docker+4
Network
Published Jan 12, 2026
Page 1 of 15
CVE-2025-59171
HIGH7.5

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

advantech / deviceon\/iedge
Network
Published Nov 6, 2025
CVE-2025-64302
MEDIUM6.4

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.

advantech / deviceon\/iedge
Network
Published Nov 6, 2025
CVE-2025-62630
HIGH8.8

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

advantech / deviceon\/iedge
Network
Published Nov 6, 2025
CVE-2025-58423
HIGH8.8

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

advantech / deviceon\/iedge
Network
Published Nov 6, 2025
CVE-2024-50359
HIGH7.2

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "scan_ap" API which are not properly sanitized before being concatenated to OS level commands.

advantech / eki-6333ac-2g_firmware+2
Network
Published Nov 26, 2024
CVE-2024-50360
HIGH7.2

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "snmp_apply" API which are not properly sanitized before being concatenated to OS level commands.

advantech / eki-6333ac-2g_firmware+2
Network
Published Nov 26, 2024
CVE-2024-50358
HIGH7.2

A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.

advantech / eki-6333ac-2g_firmware+2
Network
Published Nov 26, 2024
CVE-2024-37187
MEDIUM5.7

Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

advantech / adam-5550_firmware
Adjacent
Published Sep 27, 2024
CVE-2021-40389
HIGH8.8

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

advantech / deviceon\/iedge
Local
Published Jan 28, 2022
CVE-2021-40388
HIGH8.8

A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

advantech / sq_manager
Local
Published Jan 28, 2022
CVE-2021-27437
CRITICAL9.1

The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).

advantech / wise-paas\/rmm
Network
Published May 7, 2021
CVE-2019-18231
HIGH7.5

Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.

advantech / spectre_rt_ert351_firmware
Network
Published Mar 17, 2021
CVE-2019-18235
CRITICAL9.8

Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.

advantech / spectre_rt_ert351_firmware
Network
Published Mar 17, 2021
CVE-2019-18233
MEDIUM6.1

In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.

advantech / spectre_rt_ert351_firmware
Network
Published Mar 17, 2021
CVE-2019-18257
CRITICAL9.8

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

advantech / diaganywhere
Network
Published Dec 17, 2019
CVE-2019-18227
HIGH7.5

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

advantech / wise-paas\/rmm
Network
Published Oct 31, 2019
CVE-2019-13547
CRITICAL9.8

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.

advantech / wise-paas\/rmm
Network
Published Oct 31, 2019
CVE-2019-13551
CRITICAL9.8

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.

advantech / wise-paas\/rmm
Network
Published Oct 31, 2019
CVE-2019-18229
MEDIUM6.5

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.

advantech / wise-paas\/rmm
Network
Published Oct 31, 2019