Description
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-07
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the basicstation_apply function of the Basic Station Certificate-Deletion Handler on Advantech WISE‑6610 devices. The flaw allows an attacker to inject arbitrary shell commands via the act parameter, which the device blindly executes locally. If exploited, the attacker could run any commands with the privileges of the device, potentially taking full control or disrupting operations. The description indicates that the vulnerability is remote‑accessible and has been publicly disclosed.

Affected Systems

Vulnerable firmware 1.2.1_20251110 is present on a range of Advantech WISE‑6610 models, including WISE‑6610‑NB, WISE‑6610‑EB, WISE‑6610‑TB, WISE‑6610‑JB, WISE‑6610‑CB, the EL variants (EL‑NB, EL‑EB, EL‑TB, EL‑JB, EL‑CB), and the P‑series (WISE‑6610P‑DEA, WISE‑6610P‑DNA, WISE‑6610P‑DTA). All listed models share the same affected component.

Risk and Exploitability

The ISO/IEC 27001 CVSS score is 9.4, classifying the vulnerability as Critical. The EPSS score is not disclosed, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers can trigger the flaw remotely, likely by sending a crafted request to the basicstation_apply endpoint with a malicious act value. Once the payload is received, the device executes the commands without further validation, which is a direct path to full system compromise.

Generated by OpenCVE AI on September 7, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update 1.2.4_20260821 to all affected devices.
  • Restrict external access to the Basic Station Certificate‑Deletion interface, allowing only trusted administrative hosts.
  • Verify that input handling for the act parameter is properly sanitised or escaped, and consider disabling or limiting the basicstation_apply functionality if not needed.

Generated by OpenCVE AI on September 7, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
First Time appeared Advantech
Advantech wise-6610-cb
Advantech wise-6610-eb
Advantech wise-6610-el-cb
Advantech wise-6610-el-eb
Advantech wise-6610-el-jb
Advantech wise-6610-el-nb
Advantech wise-6610-el-tb
Advantech wise-6610-jb
Advantech wise-6610-nb
Advantech wise-6610-tb
Advantech wise-6610p-dea
Advantech wise-6610p-dna
Advantech wise-6610p-dta
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*
Vendors & Products Advantech
Advantech wise-6610-cb
Advantech wise-6610-eb
Advantech wise-6610-el-cb
Advantech wise-6610-el-eb
Advantech wise-6610-el-jb
Advantech wise-6610-el-nb
Advantech wise-6610-el-tb
Advantech wise-6610-jb
Advantech wise-6610-nb
Advantech wise-6610-tb
Advantech wise-6610p-dea
Advantech wise-6610p-dna
Advantech wise-6610p-dta
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Advantech Wise-6610-cb Wise-6610-eb Wise-6610-el-cb Wise-6610-el-eb Wise-6610-el-jb Wise-6610-el-nb Wise-6610-el-tb Wise-6610-jb Wise-6610-nb Wise-6610-tb Wise-6610p-dea Wise-6610p-dna Wise-6610p-dta
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-07T06:15:42.278Z

Reserved: 2026-08-25T12:13:37.537Z

Link: CVE-2026-79697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T07:16:45.903

Modified: 2026-09-07T07:16:45.903

Link: CVE-2026-79697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T07:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')