PT-2026-86634 · Advantech · Wise-6610-Cb+12
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1 20251110. This affects the function basicstation apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4 20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wise-6610-Cb
Wise-6610-Eb
Wise-6610-El-Cb
Wise-6610-El-Eb
Wise-6610-El-Jb
Wise-6610-El-Nb
Wise-6610-El-Tb
Wise-6610-Jb
Wise-6610-Nb
Wise-6610-Tb
Wise-6610P-Dea
Wise-6610P-Dna
Wise-6610P-Dta