A command injection vulnerability (CVE-2026-79698) was identified in multiple Advantech WISE-6610 series IoT gateway devices running firmware version 1.2.1_20251110. The flaw resides in the nodered_lib_apply function within the Node-RED Library component, where manipulation of the 'act' argument allows remote command injection. The vulnerability is remotely exploitable and a public exploit is available, raising the risk of active exploitation. All major WISE-6610 variants are affected, including NB, EB, TB, JB, CB, EL, and P-series models. Advantech was notified early and responded professionally, releasing a patched firmware version 1.2.4_20260821. Users are strongly advised to upgrade to the fixed version immediately. The coordinated disclosure reflects a positive vendor response to the reported issue.