Advantech records
378 published records for vendor advantech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 8 · 2.1%
- Pre-auth RCE
- 92
- With a fix record
- 3.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')70
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')37
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer32
- CWE-121 Stack-based Buffer Overflow27
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')26
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')24
The weakness classes this vendor ships most often: where to look.
CWEAll records
378 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2016-0854Weaponized | Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer inadvantech · webaccess | Critical9.8 | — | 77.0% | Jan 14, 2016 |
60This week | CVE-2021-21805Proof of concept | An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).advantech · r-seenet · CWE-78 | Critical9.8 | — | 69.8% | Aug 5, 2021 |
57Plan | CVE-2022-2143Weaponized | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.advantech · iview · CWE-77 | Critical9.8 | — | 59.4% | Jul 22, 2022 |
54Plan | CVE-2017-16720Proof of concept | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier.advantech · webaccess · CWE-22 | Critical9.8 | — | 50.3% | Jan 5, 2018 |
51Plan | CVE-2025-52694Proof of concept | Execution of arbitrary SQL commandsadvantech · iot edge linux docker · CWE-89 | Critical9.8 | — | 40.4% | Jan 11, 2026 |
50Plan | CVE-2021-22652Weaponized | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacadvantech · iview · CWE-306 | Critical9.8 | — | 36.8% | Feb 11, 2021 |
48Plan | CVE-2014-2364Weaponized | Advantech WebAccess Stack-Based Buffer Overflowadvantech · advantech webaccess · CWE-121 | High7.5 | — | 61.4% | Jul 19, 2014 |
47Plan | CVE-2011-0340Weaponized | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as dadvantech · advantech studio · CWE-119 | Critical9.3 | — | 32.3% | May 4, 2011 |
47Plan | CVE-2016-0857No exploit | Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectadvantech · webaccess · CWE-119 | Critical9.8 | — | 28.2% | Jan 14, 2016 |
45Plan | CVE-2014-8387Proof of concept | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shelladvantech · eki-6340 firmware · CWE-78 | Critical9.0 | — | 30.9% | Nov 20, 2014 |
44Plan | CVE-2016-0856No exploit | Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vecadvantech · webaccess · CWE-119 | Critical9.8 | — | 16.7% | Jan 14, 2016 |
44Plan | CVE-2023-5642No exploit | Advantech R-SeeNet Unauthenticated Read/Writeadvantech · r-seenet · CWE-200 | Critical9.8 | — | 16.7% | Oct 18, 2023 |
44Plan | CVE-2022-2139No exploit | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary coadvantech · iview · CWE-23 | Critical9.8 | — | 15.6% | Jul 22, 2022 |
43Plan | CVE-2021-21801Proof of concept | This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications.advantech · r-seenet · CWE-79 | Medium6.1 | — | 63.4% | Jul 16, 2021 |
43Plan | CVE-2018-6911Proof of concept | The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a singadvantech · webaccess · CWE-78 | Critical9.8 | — | 12.8% | Feb 13, 2018 |
43Plan | CVE-2021-22658No exploit | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Admadvantech · iview · CWE-89 | Critical9.8 | — | 12.7% | Feb 11, 2021 |
43Plan | CVE-2014-9208Proof of concept | Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitraadvantech · webaccess · CWE-119 | Critical10.0 | — | 9.3% | Sep 11, 2015 |
43Plan | CVE-2011-0488No exploit | Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and Iadvantech · advantech studio · CWE-119 | Critical10.0 | — | 8.6% | Jan 18, 2011 |
42Plan | CVE-2021-38408No exploit | A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the lengadvantech · webaccess · CWE-121 | Critical9.8 | — | 11.6% | Sep 9, 2021 |
42Plan | CVE-2019-10993No exploit | In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute aadvantech · webaccess · CWE-119 | Critical9.8 | — | 10.7% | Jun 28, 2019 |
42Plan | CVE-2021-38389No exploit | Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely executeadvantech · webaccess · CWE-121 | Critical9.8 | — | 10.4% | Oct 18, 2021 |
42Plan | CVE-2020-12002No exploit | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-121 | Critical9.8 | — | 9.1% | May 8, 2020 |
42Plan | CVE-2019-10991No exploit | In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validationadvantech · webaccess · CWE-787 | Critical9.8 | — | 9.0% | Jun 28, 2019 |
42Plan | CVE-2019-10989No exploit | In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation oadvantech · webaccess · CWE-787 | Critical9.8 | — | 8.6% | Jun 28, 2019 |
42Plan | CVE-2012-0242Proof of concept | Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string sadvantech · advantech webaccess · CWE-134 | Critical10.0 | — | 7.2% | Feb 21, 2012 |
- CVE-2016-085462This week
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in
CriticalCVSS 9.8WeaponizedEPSS 77%advantech · webaccessJan 14, 2016
- CVE-2021-2180560This week
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).
CriticalCVSS 9.8Proof of conceptEPSS 70%advantech · r-seenetAug 5, 2021
- CVE-2022-214357Plan
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.
CriticalCVSS 9.8WeaponizedEPSS 59%advantech · iviewJul 22, 2022
- CVE-2017-1672054Plan
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier.
CriticalCVSS 9.8Proof of conceptEPSS 50%advantech · webaccessJan 5, 2018
- CVE-2025-5269451Plan
Execution of arbitrary SQL commands
CriticalCVSS 9.8Proof of conceptEPSS 40%advantech · iot edge linux dockerJan 11, 2026
- CVE-2021-2265250Plan
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attac
CriticalCVSS 9.8WeaponizedEPSS 37%advantech · iviewFeb 11, 2021
- CVE-2014-236448Plan
Advantech WebAccess Stack-Based Buffer Overflow
HighCVSS 7.5WeaponizedEPSS 61%advantech · advantech webaccessJul 19, 2014
- CVE-2011-034047Plan
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as d
CriticalCVSS 9.3WeaponizedEPSS 32%advantech · advantech studioMay 4, 2011
- CVE-2016-085747Plan
Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vect
CriticalCVSS 9.8No exploitEPSS 28%advantech · webaccessJan 14, 2016
- CVE-2014-838745Plan
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell
CriticalCVSS 9.0Proof of conceptEPSS 31%advantech · eki-6340 firmwareNov 20, 2014
- CVE-2016-085644Plan
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vec
CriticalCVSS 9.8No exploitEPSS 17%advantech · webaccessJan 14, 2016
- CVE-2023-564244Plan
Advantech R-SeeNet Unauthenticated Read/Write
CriticalCVSS 9.8No exploitEPSS 17%advantech · r-seenetOct 18, 2023
- CVE-2022-213944Plan
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary co
CriticalCVSS 9.8No exploitEPSS 16%advantech · iviewJul 22, 2022
- CVE-2021-2180143Plan
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications.
MediumCVSS 6.1Proof of conceptEPSS 63%advantech · r-seenetJul 16, 2021
- CVE-2018-691143Plan
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a sing
CriticalCVSS 9.8Proof of conceptEPSS 13%advantech · webaccessFeb 13, 2018
- CVE-2021-2265843Plan
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Adm
CriticalCVSS 9.8No exploitEPSS 13%advantech · iviewFeb 11, 2021
- CVE-2014-920843Plan
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitra
CriticalCVSS 10.0Proof of conceptEPSS 9%advantech · webaccessSep 11, 2015
- CVE-2011-048843Plan
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and I
CriticalCVSS 10.0No exploitEPSS 9%advantech · advantech studioJan 18, 2011
- CVE-2021-3840842Plan
A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the leng
CriticalCVSS 9.8No exploitEPSS 12%advantech · webaccessSep 9, 2021
- CVE-2019-1099342Plan
In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute a
CriticalCVSS 9.8No exploitEPSS 11%advantech · webaccessJun 28, 2019
- CVE-2021-3838942Plan
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute
CriticalCVSS 9.8No exploitEPSS 10%advantech · webaccessOct 18, 2021
- CVE-2020-1200242Plan
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
CriticalCVSS 9.8No exploitEPSS 9%advantech · webaccessMay 8, 2020
- CVE-2019-1099142Plan
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation
CriticalCVSS 9.8No exploitEPSS 9%advantech · webaccessJun 28, 2019
- CVE-2019-1098942Plan
In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation o
CriticalCVSS 9.8No exploitEPSS 9%advantech · webaccessJun 28, 2019
- CVE-2012-024242Plan
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string s
CriticalCVSS 10.0Proof of conceptEPSS 7%advantech · advantech webaccessFeb 21, 2012