Impact
The flaw allows a remote attacker to supply an arbitrary value for the delete_file parameter in the /cgi-bin/luci/admin/openvpn_apply CGI script, resulting in execution of arbitrary OS commands by the web server process (CWE-77, CWE-78). Because the commands run with the server’s privileges, an attacker could compromise the confidentiality, integrity, and availability of the entire device.
Affected Systems
Advantech WISE-6610 devices running firmware 1.2.1_20251110 are affected. No other firmware versions are listed. The vulnerability lies in the publicly accessible Background Management component and is constrained to the openvpn_apply CGI script; other firmware revisions are not indicated in the data.
Risk and Exploitability
The CVSS base score of 8.6 places the issue in the High severity range. An EPSS score of 16% indicates a moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the exposed endpoint remotely without local privileges. Because the injected commands run under the web server’s user rights, the risk of device compromise is appreciable.
OpenCVE Enrichment