PT-2025-45355 · Advantech · Webaccess/Vpn

·

CVE-2025-34238

·

Published

2025-10-31

·

Updated

2025-11-07

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Advantech WebAccess/VPN versions prior to 1.1.5
Description The software contains a path traversal flaw in the AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() function. An authenticated network administrator can exploit this to read and return the contents of arbitrary files accessible to the web user (www-data). The issue allows traversal via an absolute path.
Recommendations Update to version 1.1.5 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13986
CVE-2025-34238

Affected Products

Webaccess/Vpn