Impact
A command injection flaw exists in the basicstation_apply function of the Basic Station Certificate-Deletion Handler on Advantech WISE‑6610 devices. The flaw allows an attacker to inject arbitrary shell commands via the act parameter, which the device blindly executes locally. If exploited, the attacker could run any commands with the privileges of the device, potentially taking full control or disrupting operations. The description indicates that the vulnerability is remote‑accessible and has been publicly disclosed.
Affected Systems
Vulnerable firmware 1.2.1_20251110 is present on a range of Advantech WISE‑6610 models, including WISE‑6610‑NB, WISE‑6610‑EB, WISE‑6610‑TB, WISE‑6610‑JB, WISE‑6610‑CB, the EL variants (EL‑NB, EL‑EB, EL‑TB, EL‑JB, EL‑CB), and the P‑series (WISE‑6610P‑DEA, WISE‑6610P‑DNA, WISE‑6610P‑DTA). All listed models share the same affected component.
Risk and Exploitability
The ISO/IEC 27001 CVSS score is 9.4, classifying the vulnerability as Critical. The EPSS score is not disclosed, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers can trigger the flaw remotely, likely by sending a crafted request to the basicstation_apply endpoint with a malicious act value. Once the payload is received, the device executes the commands without further validation, which is a direct path to full system compromise.
OpenCVE Enrichment