← Terug naar overzicht

A command injection vulnerability (CVE-2026-79698) was identified in multiple Advantech WISE-6610 series IoT gateway devices running firmware version 1.2.1_20251110. The flaw resides in the nodered_lib_apply function within the Node-RED Library component, where manipulation of the 'act' argument allows remote command injection. The vulnerability is remotely exploitable and a public exploit is available, raising the risk of active exploitation. All major WISE-6610 variants are affected, including NB, EB, TB, JB, CB, EL, and P-series models. Advantech was notified early and responded professionally, releasing a patched firmware version 1.2.4_20260821. Users are strongly advised to upgrade to the fixed version immediately. The coordinated disclosure reflects a positive vendor response to the reported issue.

Affected products

  • Advantech WISE-6610-CB
  • Advantech WISE-6610-EB
  • Advantech WISE-6610-EL-CB
  • Advantech WISE-6610-EL-EB
  • Advantech WISE-6610-EL-JB
  • Advantech WISE-6610-EL-NB
  • Advantech WISE-6610-EL-TB
  • Advantech WISE-6610-JB
  • Advantech WISE-6610-NB
  • Advantech WISE-6610-TB
  • Advantech WISE-6610P-DEA
  • Advantech WISE-6610P-DNA
  • Advantech WISE-6610P-DTA

Related CVE's

  • CVE-2026-79698

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure