Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Advantech — Vulnerabilities & Security Advisories 159

Browse all 159 CVE security advisories affecting Advantech. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Advantech specializes in industrial automation, providing embedded computing hardware and IoT solutions for manufacturing and infrastructure sectors. The company’s extensive product portfolio, which includes edge gateways and panel PCs, has resulted in a significant vulnerability footprint, with 139 Common Vulnerabilities and Exposures (CVEs) currently recorded. Historical analysis reveals that these security flaws predominantly stem from Remote Code Execution (RCE) and Cross-Site Scripting (XSS) issues, often arising from unpatched web management interfaces or embedded Linux components. Additionally, several instances of privilege escalation and buffer overflow vulnerabilities have been documented, highlighting risks associated with legacy firmware and default configurations. While no single catastrophic incident has defined the brand’s public security history, the sheer volume of disclosed defects underscores persistent challenges in maintaining secure codebases across diverse industrial environments. This pattern necessitates rigorous patch management and network segmentation for organizations relying on Advantech infrastructure to mitigate potential exploitation vectors.

CVE ID Title CVSS Severity Published
CVE-2026-73177 研华EKI-1242EIMS固件升级机制缺乏完整性验证 — EKI-1242IEIMS CWE-345 8.6 High 2026-09-16
CVE-2026-73176 Advantech EKI-1242IEIMS V1.06.01 OS命令注入漏洞 — EKI-1242IEIMS CWE-78 8.6 High 2026-09-16
CVE-2026-73175 Advantech EKI-1242EIMS v1.06.01 资源耗尽致DoS — EKI-1242IEIMS CWE-400 7.1 High 2026-09-16
CVE-2026-73174 Advantech EKI-1242EIMS V1.06.01 明文传输敏感信息漏洞 — EKI-1242IEIMS CWE-319 8.7 High 2026-09-16
CVE-2026-73173 Advantech EKI-1242EIMS V1.06.01 缺失认证漏洞 — EKI-1242IEIMS CWE-306 8.8 High 2026-09-16
CVE-2026-73172 Advantech EKI-1242EIMS V1.06.01 命令注入漏洞 — EKI-1242IEIMS CWE-78 9.3 Critical 2026-09-16
CVE-2026-73171 Advantech EKI-1242EIMS V1.06.01 备份路径控制漏洞 — EKI-1242IEIMS CWE-73 8.6 High 2026-09-16
CVE-2026-73170 Advantech EKI-1242EIMS V1.06.01 代码注入漏洞 — EKI-1242IEIMS CWE-94 8.6 High 2026-09-16
CVE-2026-73169 Advantech EKI-1242EIMS V1.06.01 存储型XSS — EKI-1242IEIMS CWE-79 6.3 Medium 2026-09-16
CVE-2026-73167 Advantech EKI-1242IEIMS V1.06.01 操作系统命令注入 — EKI-1242IEIMS CWE-78 8.6 High 2026-09-16
CVE-2026-73166 Advantech EKI-1242IEIMS V1.06.01 代码注入漏洞 — EKI-1242IEIMS CWE-94 8.6 High 2026-09-16
CVE-2026-73165 Advantech EKI-1242IEIMS V1.06.01 命令注入 — EKI-1242IEIMS CWE-78 8.6 High 2026-09-16
CVE-2026-73164 研华EKI-1242IEIMS V1.06.01 OS命令注入漏洞 — EKI-1242IEIMS CWE-78 8.6 High 2026-09-16
CVE-2026-73163 Advantech EKI-1242IEIMS V1.06.01命令注入 — EKI-1242IEIMS CWE-78 8.6 High 2026-09-16
CVE-2026-19535 Advantech EKI-1242IEIMS V1.06.01 CSRF漏洞 — EKI-1242IEIMS CWE-352 8.6 High 2026-09-16
CVE-2026-79698 Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection — WISE-6610-NB CWE-77 9.9 Critical 2026-09-07
CVE-2026-79697 Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection — WISE-6610-NB CWE-77 9.9 Critical 2026-09-07
CVE-2026-14162 Advantech|Hospital Quering Management - Missing Authentication — Hospital Quering Management CWE-306 9.8 Critical 2026-06-30
CVE-2026-14161 Advantech|Hospital Queuing Management - Sensitive Data Exposure — Hospital Queuing Management CWE-200 7.5 High 2026-06-30
CVE-2026-6888 SQL Injection Vulnerability — SaaS Composer 7.2 High 2026-05-13
CVE-2026-2670 Advantech WISE-6610-NB Background Management openvpn_apply os command injection — WISE-6610-NB CWE-78 7.2 High 2026-02-18
CVE-2025-52694 Execution of arbitrary SQL commands — IoTSuite and IoT Edge Products 10.0 Critical 2026-01-12
CVE-2025-67653 Advantech WebAccess/SCADA Path Traversal — WebAccess/SCADA CWE-22 4.3 Medium 2025-12-18
CVE-2025-46268 Advantech WebAccess/SCADA SQL Injection — WebAccess/SCADA CWE-89 6.3 Medium 2025-12-18
CVE-2025-14848 Advantech WebAccess/SCADA Absolute Path Traversal — WebAccess/SCADA CWE-36 4.3 Medium 2025-12-18
CVE-2025-14849 Advantech WebAccess/SCADA Unrestricted Upload of File with Dangerous Type — WebAccess/SCADA CWE-434 8.8 High 2025-12-18
CVE-2025-14850 Advantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted Directory — WebAccess/SCADA CWE-22 8.1 High 2025-12-18
CVE-2025-14252 Advantech SUSI 安全漏洞 — SUSI 7.8 High 2025-12-16
CVE-2025-13373 Advantech iView SQL Injection — iView CWE-89 7.5 High 2025-12-04
CVE-2025-58423 Advantech DeviceOn/iEdge Path Traversal — DeviceOn/iEdge CWE-22 8.8 High 2025-11-06

This page lists every published CVE security advisory associated with Advantech. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.