Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Advantech — Vulnerabilities & Security Advisories 159

Browse all 159 CVE security advisories affecting Advantech. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Advantech specializes in industrial automation, providing embedded computing hardware and IoT solutions for manufacturing and infrastructure sectors. The company’s extensive product portfolio, which includes edge gateways and panel PCs, has resulted in a significant vulnerability footprint, with 139 Common Vulnerabilities and Exposures (CVEs) currently recorded. Historical analysis reveals that these security flaws predominantly stem from Remote Code Execution (RCE) and Cross-Site Scripting (XSS) issues, often arising from unpatched web management interfaces or embedded Linux components. Additionally, several instances of privilege escalation and buffer overflow vulnerabilities have been documented, highlighting risks associated with legacy firmware and default configurations. While no single catastrophic incident has defined the brand’s public security history, the sheer volume of disclosed defects underscores persistent challenges in maintaining secure codebases across diverse industrial environments. This pattern necessitates rigorous patch management and network segmentation for organizations relying on Advantech infrastructure to mitigate potential exploitation vectors.

CVE ID Title CVSS Severity Published
CVE-2025-59171 Advantech DeviceOn/iEdge Path Traversal — DeviceOn/iEdge CWE-22 7.5 High 2025-11-06
CVE-2025-62630 Advantech DeviceOn/iEdge Path Traversal — DeviceOn/iEdge CWE-22 8.8 High 2025-11-06
CVE-2025-64302 Advantech DeviceOn/iEdge Cross-site Scripting — DeviceOn/iEdge CWE-79 6.4 Medium 2025-11-06
CVE-2022-50595 Advantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCE — iView CWE-89 9.8 - 2025-11-06
CVE-2022-50591 Advantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information Disclosure — iView CWE-89 9.1 - 2025-11-06
CVE-2022-50593 Advantech iView < v5.7.04 Build 6425 search_term Parameter SQL Injection RCE — iView CWE-89 9.8 - 2025-11-06
CVE-2022-50592 Advantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCE — iView CWE-89 9.8 - 2025-11-06
CVE-2022-50594 Advantech iView < v5.7.04 Build 6425 data Parameter SQL Injection Information Disclosure — iView CWE-89 7.5 - 2025-11-06
CVE-2025-34247 Advantech WebAccess/VPN < 1.1.5 SQL Injection via NetworksController.addNetworkAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34246 Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxPrevalidationController.ajaxAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34245 Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxStandaloneVpnClientsController.ajaxAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34244 Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxDeviceFwRulesAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34243 Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxNetworkFwRulesAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34242 Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxNetworkController.ajaxAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34241 Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxDeviceController.ajaxDeviceAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34240 Advantech WebAccess/VPN < 1.1.5 SQL Injection via AppManagementController.appUpgradeAction() — WebAccess/VPN CWE-89 6.5 - 2025-11-06
CVE-2025-34239 Advantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction() — WebAccess/VPN CWE-78 7.2 - 2025-11-06
CVE-2025-34238 Advantech WebAccess/VPN < 1.1.5 Path Traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() — WebAccess/VPN CWE-22 4.9 - 2025-11-06
CVE-2025-34237 Advantech WebAccess/VPN < 1.1.5 Stored XSS via StandaloneVpnClientsController.addStandaloneVpnClientAction() — WebAccess/VPN CWE-79 5.4 - 2025-11-06
CVE-2025-34236 Advantech WebAccess/VPN < 1.1.5 Stored XSS via NetworksController.addNetworkAction() — WebAccess/VPN CWE-79 5.4 - 2025-11-06
CVE-2025-53509 Advantech iView Argument Injection — iView CWE-88 6.5 Medium 2025-07-10
CVE-2025-52459 Advantech iView Argument Injection — iView CWE-88 6.5 Medium 2025-07-10
CVE-2025-53515 Advantech iView SQL Injection — iView CWE-89 8.8 High 2025-07-10
CVE-2025-52577 Advantech iView SQL Injection — iView CWE-89 8.8 High 2025-07-10
CVE-2025-53475 Advantech iView SQL Injection — iView CWE-89 8.8 High 2025-07-10
CVE-2025-46704 Advantech iView Path Traversal — iView CWE-22 4.3 Medium 2025-07-10
CVE-2025-48891 Advantech iView SQL Injection — iView CWE-89 7.6 High 2025-07-10
CVE-2025-41442 Advantech iView Cross-site Scripting — iView CWE-79 5.4 Medium 2025-07-10
CVE-2025-53519 Advantech iView Cross-site Scripting — iView CWE-79 5.4 Medium 2025-07-10
CVE-2025-53397 Advantech iView Cross-site Scripting — iView CWE-79 5.4 Medium 2025-07-10

This page lists every published CVE security advisory associated with Advantech. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.