vciy

CVEs we hold for Advantech

Records whose assigning authority named Advantech as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-79698Advantech WISE-6610-NB Node-RED nodered_lib_apply command injectionAdvantech WISE-6610P-DTA
CVE-2026-79697Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injectionAdvantech WISE-6610P-DTA
CVE-2026-73177no title heldAdvantech EKI-1242EIMS
CVE-2026-73176no title heldAdvantech EKI-1242EIMS
CVE-2026-73175no title heldAdvantech EKI-1242EIMS
CVE-2026-73174no title heldAdvantech EKI-1242EIMS
CVE-2026-73173no title heldAdvantech EKI-1242EIMS
CVE-2026-73172no title heldAdvantech EKI-1242EIMS
CVE-2026-73171no title heldAdvantech EKI-1242EIMS
CVE-2026-73170no title heldAdvantech EKI-1242EIMS
CVE-2026-73169no title heldAdvantech EKI-1242EIMS
CVE-2026-73167no title heldAdvantech EKI-1242EIMS
CVE-2026-73166no title heldAdvantech EKI-1242EIMS
CVE-2026-73165no title heldAdvantech EKI-1242EIMS
CVE-2026-73164no title heldAdvantech EKI-1242EIMS
CVE-2026-73163no title heldAdvantech EKI-1242EIMS
CVE-2026-6888SQL Injection VulnerabilityAdvantech ECOWatch SaaS-Composer
CVE-2026-2670Advantech WISE-6610-NB Background Management openvpn_apply os command injectionAdvantech WISE-6610P-DTA
CVE-2026-19535no title heldAdvantech EKI-1242EIMS
CVE-2026-14162Advantech|Hospital Quering Management - Missing AuthenticationAdvantech Hospital Quering Management
CVE-2026-14161Advantech|Hospital Queuing Management - Sensitive Data ExposureAdvantech Hospital Queuing Management
CVE-2025-67653Advantech WebAccess/SCADA Path TraversalAdvantech WebAccess/SCADA
CVE-2025-64302Advantech DeviceOn/iEdge Cross-site ScriptingAdvantech DeviceOn/iEdge
CVE-2025-62630Advantech DeviceOn/iEdge Path TraversalAdvantech DeviceOn/iEdge
CVE-2025-59171Advantech DeviceOn/iEdge Path TraversalAdvantech DeviceOn/iEdge
CVE-2025-58423Advantech DeviceOn/iEdge Path TraversalAdvantech DeviceOn/iEdge
CVE-2025-53519Advantech iView Cross-site ScriptingAdvantech iView
CVE-2025-53515Advantech iView SQL InjectionAdvantech iView
CVE-2025-53509Advantech iView Argument InjectionAdvantech iView
CVE-2025-53475Advantech iView SQL InjectionAdvantech iView
CVE-2025-53397Advantech iView Cross-site ScriptingAdvantech iView
CVE-2025-52694Execution of arbitrary SQL commandsAdvantech IoTSuite and IoT Edge Products
CVE-2025-52577Advantech iView SQL InjectionAdvantech iView
CVE-2025-52459Advantech iView Argument InjectionAdvantech iView
CVE-2025-48891Advantech iView SQL InjectionAdvantech iView
CVE-2025-48470Stored Cross site Scripting (XSS)Advantech Wireless Sensing and Equipment (WISE)
CVE-2025-48469Unauthenticated Firmware UploadAdvantech Wireless Sensing and Equipment (WISE)
CVE-2025-48468Open JTAG Debug PortAdvantech Wireless Sensing and Equipment (WISE)
CVE-2025-48467Denial of Service via Malformed Modbus PacketsAdvantech Wireless Sensing and Equipment (WISE)
CVE-2025-48466Modbus Command Injection without AuthenticationAdvantech Wireless Sensing and Equipment (WISE)
CVE-2025-48463Unencrypted HTTP CommunicationAdvantech Wireless Sensing and Equipment (WISE)
CVE-2025-48462Login Session ExhaustionAdvantech Wireless Sensing and Equipment (WISE)
CVE-2025-48461Weak Session Cookie EntropyAdvantech Wireless Sensing and Equipment (WISE)
CVE-2025-46704Advantech iView Path TraversalAdvantech iView
CVE-2025-46268Advantech WebAccess/SCADA SQL InjectionAdvantech WebAccess/SCADA
CVE-2025-41442Advantech iView Cross-site ScriptingAdvantech iView
CVE-2025-34266Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menusAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34265Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via rule-enginesAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34264Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via dog/{agentId}Advantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34263Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/dashboards/menusAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34262Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}Advantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34261Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/Advantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34260Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/scheduleAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34259Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/buildingAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34258Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/planAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34257Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/definedAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34256Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication BypassAdvantech Co., Ltd. WISE-DeviceOn Server
CVE-2025-34247Advantech WebAccess/VPN < 1.1.5 SQL Injection via NetworksController.addNetworkAction()Advantech WebAccess/VPN
CVE-2025-34246Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxPrevalidationController.ajaxAction()Advantech WebAccess/VPN
CVE-2025-34245Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxStandaloneVpnClientsController.ajaxAction()Advantech WebAccess/VPN
CVE-2025-34244Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxDeviceFwRulesAction()Advantech WebAccess/VPN
CVE-2025-34243Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxNetworkFwRulesAction()Advantech WebAccess/VPN
CVE-2025-34242Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxNetworkController.ajaxAction()Advantech WebAccess/VPN
CVE-2025-34241Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxDeviceController.ajaxDeviceAction()Advantech WebAccess/VPN
CVE-2025-34240Advantech WebAccess/VPN < 1.1.5 SQL Injection via AppManagementController.appUpgradeAction()Advantech WebAccess/VPN
CVE-2025-34239Advantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()Advantech WebAccess/VPN
CVE-2025-34238Advantech WebAccess/VPN < 1.1.5 Path Traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileA…Advantech WebAccess/VPN
CVE-2025-34237Advantech WebAccess/VPN < 1.1.5 Stored XSS via StandaloneVpnClientsController.addStandaloneVpnClientAction()Advantech WebAccess/VPN
CVE-2025-34236Advantech WebAccess/VPN < 1.1.5 Stored XSS via NetworksController.addNetworkAction()Advantech WebAccess/VPN
CVE-2025-14850Advantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted DirectoryAdvantech WebAccess/SCADA
CVE-2025-14849Advantech WebAccess/SCADA Unrestricted Upload of File with Dangerous TypeAdvantech WebAccess/SCADA
CVE-2025-14848Advantech WebAccess/SCADA Absolute Path TraversalAdvantech WebAccess/SCADA
CVE-2025-14252no title heldAdvantech SUSI
CVE-2025-13373Advantech iView SQL InjectionAdvantech iView
CVE-2024-50377no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50376no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50375no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50374no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50373no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50372no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50371no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50370no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50369no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50368no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50367no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50366no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50365no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50364no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50363no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50362no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50361no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50360no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50359no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-50358no title heldAdvantech EKI-6333AC-1GPO
CVE-2024-39364Advantech ADAM-5630 Missing Authentication for Critical FunctionAdvantech ADAM-5630
CVE-2024-39275Advantech ADAM-5630 Use of Persistent Cookies Containing Sensitive InformationAdvantech ADAM-5630
CVE-2024-38308Advantech ADAM-5550 Cross-site ScriptingAdvantech ADAM 5550
CVE-2024-37187Advantech ADAM-5550 Weak Encoding for PasswordAdvantech ADAM 5550
CVE-2024-34542Advantech ADAM-5630 Weak Encoding for PasswordAdvantech ADAM-5630
CVE-2024-28948Advantech ADAM-5630 Cross-Site Request ForgeryAdvantech ADAM-5630
CVE-2024-2453Advantech WebAccess/SCADA SQL InjectionAdvantech WebAccess/SCADA
CVE-2023-5642Advantech R-SeeNet Unauthenticated Read/WriteAdvantech R-SeeNet
CVE-2023-52335Advantech iView ConfigurationServlet SQL Injection Information Disclosure VulnerabilityAdvantech iView
CVE-2023-4215Advantech WebAccess Debug Messages Revealing Unnecessary InformationAdvantech WebAccess
CVE-2023-4203Stored Cross-Site ScriptingAdvantech EKI-1521
CVE-2023-4202Stored Cross-Site ScriptingAdvantech EKI-1521
CVE-2023-3983no title heldn/a Advantech iView
CVE-2023-32628no title heldAdvantech WebAccess/SCADA
CVE-2023-3256Advantech R-SeeNet External Control of File Name or PathAdvantech R-SeeNet
CVE-2023-32540no title heldAdvantech WebAccess/SCADA
CVE-2023-2866Advantech WebAccess Insufficient Type DistinctionAdvantech WebAccess/SCADA
CVE-2023-2611Advantech R-SeeNet Use of Hard-coded CredentialsAdvantech R-SeeNet
CVE-2023-2575Authenticated Buffer OverflowAdvantech EKI-1521
CVE-2023-2574Authenticated Command InjectionAdvantech EKI-1521
CVE-2023-2573Authenticated Command InjectionAdvantech EKI-1521
CVE-2023-22450no title heldAdvantech WebAccess/SCADA
CVE-2023-1437CVE-2023-1437Advantech WebAccess/SCADA
CVE-2022-50595Advantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCEAdvantech iView
CVE-2022-50594Advantech iView < v5.7.04 Build 6425 data Parameter SQL Injection Information DisclosureAdvantech iView
CVE-2022-50593Advantech iView < v5.7.04 Build 6425 search_term Parameter SQL Injection RCEAdvantech iView
CVE-2022-50592Advantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCEAdvantech iView
CVE-2022-50591Advantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information DisclosureAdvantech iView
CVE-2022-3387no title heldAdvantech R-SeeNet
CVE-2022-3386no title heldAdvantech R-SeeNet
CVE-2022-3385no title heldAdvantech R-SeeNet
CVE-2022-3323no title heldn/a Advantech iView
CVE-2022-22987Advantech ADAM-3600Advantech ADAM-3600
CVE-2022-2143Advantech iViewAdvantech iView iView
CVE-2022-2142Advantech iViewAdvantech iView iView
CVE-2022-2139Advantech iViewAdvantech iView iView
CVE-2022-2138Advantech iViewAdvantech iView iView
CVE-2022-2137Advantech iViewAdvantech iView iView
CVE-2022-2136Advantech iViewAdvantech iView iView
CVE-2022-2135Advantech iViewAdvantech iView iView
CVE-2021-42706AzeoTech DAQFactoryAdvantech HMI Designer
CVE-2021-42703AzeoTech DAQFactoryAdvantech HMI Designer
CVE-2021-38431Advantech WebAccess SCADAAdvantech WebAccess SCADA
CVE-2021-38408no title heldn/a Advantech WebAccess
CVE-2021-38389Advantech WebAccessAdvantech WebAccess
CVE-2021-33023Advantech WebAccessAdvantech WebAccess
CVE-2021-32956no title heldn/a Advantech WebAccess/SCADA
CVE-2021-32954no title heldn/a Advantech WebAccess/SCADA
CVE-2021-32951Advantech WebAccess/NMS Improper AuthenticationAdvantech WebAccess/NMS
CVE-2021-27436no title heldn/a Advantech WebAccess/SCADA
CVE-2021-22669no title heldn/a Advantech WebAccess/SCADA
CVE-2021-22658no title heldn/a Advantech iView
CVE-2021-22656no title heldn/a Advantech iView
CVE-2021-22654no title heldn/a Advantech iView
CVE-2021-22652no title heldn/a Advantech iView
CVE-2021-21937no title heldn/a Advantech
CVE-2021-21936no title heldn/a Advantech
CVE-2021-21935no title heldn/a Advantech
CVE-2021-21934no title heldn/a Advantech
CVE-2021-21933no title heldn/a Advantech
CVE-2021-21932no title heldn/a Advantech
CVE-2021-21931no title heldn/a Advantech
CVE-2021-21930no title heldn/a Advantech
CVE-2021-21929no title heldn/a Advantech
CVE-2021-21928no title heldn/a Advantech
CVE-2021-21927no title heldn/a Advantech
CVE-2021-21926no title heldn/a Advantech
CVE-2021-21925no title heldn/a Advantech
CVE-2021-21924no title heldn/a Advantech
CVE-2021-21923no title heldn/a Advantech
CVE-2021-21922no title heldn/a Advantech
CVE-2021-21921no title heldn/a Advantech
CVE-2021-21920no title heldn/a Advantech
CVE-2021-21919no title heldn/a Advantech
CVE-2021-21918no title heldn/a Advantech
CVE-2021-21917no title heldn/a Advantech
CVE-2021-21916no title heldn/a Advantech
CVE-2021-21915no title heldn/a Advantech
CVE-2021-21912no title heldn/a Advantech
CVE-2021-21911no title heldn/a Advantech
CVE-2021-21910no title heldn/a Advantech
CVE-2021-21805no title heldn/a Advantech
CVE-2021-21804no title heldn/a Advantech
CVE-2021-21803no title heldn/a Advantech
CVE-2021-21802no title heldn/a Advantech
CVE-2021-21801no title heldn/a Advantech
CVE-2021-21800no title heldn/a Advantech
CVE-2021-21799no title heldn/a Advantech
CVE-2020-25161no title heldn/a Advantech WebAccess/SCADA
CVE-2020-25157no title heldn/a Advantech R-SeeNet
CVE-2020-16245no title heldn/a Advantech iView
CVE-2020-16229no title heldn/a Advantech WebAccess HMI Designer
CVE-2020-16217no title heldn/a Advantech WebAccess HMI Designer
CVE-2020-16215no title heldn/a Advantech WebAccess HMI Designer
CVE-2020-16213no title heldn/a Advantech WebAccess HMI Designer
CVE-2020-16211no title heldn/a Advantech WebAccess HMI Designer
CVE-2020-16207no title heldn/a Advantech WebAccess HMI Designer
CVE-2020-14507no title heldn/a Advantech iView
CVE-2020-14505no title heldn/a Advantech iView
CVE-2020-14503no title heldn/a Advantech iView
CVE-2020-14501no title heldn/a Advantech iView
CVE-2020-14499no title heldn/a Advantech iView
CVE-2020-14497no title heldn/a Advantech iView
CVE-2020-13555no title heldn/a Advantech
CVE-2020-13554no title heldn/a Advantech
CVE-2020-13553no title heldn/a Advantech

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.