Description
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."
Published: 2026-02-18
Score: 8.6 High
EPSS: 12.8% Moderate
KEV: No
Impact: Remote Command Execution
Action: Check for Updates
AI Analysis

Impact

The flaw allows a remote attacker to supply an arbitrary value for the delete_file parameter in the /cgi-bin/luci/admin/openvpn_apply CGI script, resulting in execution of arbitrary OS commands by the web server process (CWE-77, CWE-78). Because the commands run with the server’s privileges, an attacker could compromise the confidentiality, integrity, and availability of the entire device.

Affected Systems

Advantech WISE-6610 devices running firmware 1.2.1_20251110 are affected. No other firmware versions are listed. The vulnerability lies in the publicly accessible Background Management component and is constrained to the openvpn_apply CGI script; other firmware revisions are not indicated in the data.

Risk and Exploitability

The CVSS base score of 8.6 places the issue in the High severity range. An EPSS score of 12% indicates a moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the exposed endpoint remotely without local privileges. Because the injected commands run under the web server’s user rights, the risk of device compromise is appreciable.

Generated by OpenCVE AI on September 7, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Advantech firmware upgrade to version 1.2.4_20260821.
  • Block or restrict external access to /cgi-bin/luci/admin/openvpn_apply via firewall or ACLs to limit exposure to trusted networks.
  • Enforce strict input validation for the delete_file parameter, ensuring that only permitted values or file names are accepted, thereby preventing command injection.
  • Enable logging of delete_file requests and monitor for anomalous values or patterns indicative of exploitation attempts.

Generated by OpenCVE AI on September 7, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 06:30:00 +0000


Mon, 07 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."
Title Advantech WISE-6610 Background Management openvpn_apply os command injection Advantech WISE-6610-NB Background Management openvpn_apply os command injection
First Time appeared Advantech wise-6610-cb
Advantech wise-6610-eb
Advantech wise-6610-el-cb
Advantech wise-6610-el-eb
Advantech wise-6610-el-jb
Advantech wise-6610-el-nb
Advantech wise-6610-el-tb
Advantech wise-6610-jb
Advantech wise-6610-nb
Advantech wise-6610-tb
Advantech wise-6610p-dea
Advantech wise-6610p-dna
Advantech wise-6610p-dta
CPEs cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*
Vendors & Products Advantech wise-6610-cb
Advantech wise-6610-eb
Advantech wise-6610-el-cb
Advantech wise-6610-el-eb
Advantech wise-6610-el-jb
Advantech wise-6610-el-nb
Advantech wise-6610-el-tb
Advantech wise-6610-jb
Advantech wise-6610-nb
Advantech wise-6610-tb
Advantech wise-6610p-dea
Advantech wise-6610p-dna
Advantech wise-6610p-dta
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Fri, 20 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech wise-6610
Vendors & Products Advantech
Advantech wise-6610

Wed, 18 Feb 2026 21:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Advantech WISE-6610 Background Management openvpn_apply os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Advantech Wise-6610 Wise-6610-cb Wise-6610-eb Wise-6610-el-cb Wise-6610-el-eb Wise-6610-el-jb Wise-6610-el-nb Wise-6610-el-tb Wise-6610-jb Wise-6610-nb Wise-6610-tb Wise-6610p-dea Wise-6610p-dna Wise-6610p-dta
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-07T05:58:16.410Z

Reserved: 2026-02-18T09:16:43.848Z

Link: CVE-2026-2670

cve-icon Vulnrichment

Updated: 2026-02-20T19:32:43.252Z

cve-icon NVD

Status : Deferred

Published: 2026-02-18T22:16:27.360

Modified: 2026-09-07T06:17:18.777

Link: CVE-2026-2670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:45:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')