← Terug naar overzicht

A command injection vulnerability was identified in multiple Advantech WISE-6610 series devices running firmware version 1.2.1_20251110. The flaw exists in the basicstation_apply function within the Basic Station Certificate-Deletion Handler component, where manipulation of the 'act' argument enables command injection. The vulnerability can be exploited remotely and a public exploit has been disclosed. Affected models include WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, their EL variants, and WISE-6610P-DEA, WISE-6610P-DNA, and WISE-6610P-DTA. The vendor responded promptly and released a patched firmware version 1.2.4_20260821. Users are advised to upgrade immediately to mitigate the risk.

Affected products

  • Advantech WISE-6610-CB
  • Advantech WISE-6610-EB
  • Advantech WISE-6610-EL-CB
  • Advantech WISE-6610-EL-EB
  • Advantech WISE-6610-EL-JB
  • Advantech WISE-6610-EL-NB
  • Advantech WISE-6610-EL-TB
  • Advantech WISE-6610-JB
  • Advantech WISE-6610-NB
  • Advantech WISE-6610-TB
  • Advantech WISE-6610P-DEA
  • Advantech WISE-6610P-DNA
  • Advantech WISE-6610P-DTA

Related CVE's

  • CVE-2026-79697

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure