Description
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-07
Score: 9.4 Critical
EPSS: 3.2% Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A flaw in the advanced node functionalities of the Node‑RED library allows an attacker to craft a malicious "act" argument that is passed directly to the system shell, enabling arbitrary command execution from a remote source. The weakness is classified under CWE‑74 and CWE‑77, both of which represent improper handling of input that can lead to OS command injection. With a CVSS score of 9.4, the vulnerability grants full control over the affected device, jeopardizing confidentiality, integrity, and availability of the system and potentially all devices on the same network.

Affected Systems

The issue affects Advantech WISE‑6610 devices—including the CB, EB, EL‑NB, EL‑EB, EL‑TB, EL‑JB, NB, TB, JB variants and the three P‑series models (P‑DEA, P‑DNA, P‑DTA)—running firmware version 1.2.1_20251110 or earlier. All listed models are vulnerable when the Node‑RED library is present and the exploitable endpoint is accessible.

Risk and Exploitability

The vulnerability is remotely exploitable without requiring prior authentication; it relies on network access to the Node‑RED server exposed by the device. The EPSS score is 0.03 (3%), indicating a low but non‑zero probability of exploitation, and the public availability of an exploit combined with the high CVSS base score suggest a strong likelihood of real‑world attacks. The vulnerability is not currently listed in CISA’s KEV catalog, but the risk remains high for systems that remain on affected firmware versions.

Generated by OpenCVE AI on September 25, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑issued firmware upgrade 1.2.4_20260821 or later to eliminate the command‑injection vector.
  • If an immediate firmware update is not possible, block or remove external network access to the Node‑RED server, or restrict the "act" API endpoint to trusted IP ranges.
  • Apply network segmentation or firewall rules to isolate the affected devices from untrusted networks until the official patch can be deployed.

Generated by OpenCVE AI on September 25, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Advantech wise-6610
Vendors & Products Advantech wise-6610

Mon, 07 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
First Time appeared Advantech
Advantech wise-6610-cb
Advantech wise-6610-eb
Advantech wise-6610-el-cb
Advantech wise-6610-el-eb
Advantech wise-6610-el-jb
Advantech wise-6610-el-nb
Advantech wise-6610-el-tb
Advantech wise-6610-jb
Advantech wise-6610-nb
Advantech wise-6610-tb
Advantech wise-6610p-dea
Advantech wise-6610p-dna
Advantech wise-6610p-dta
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:advantech:wise-6610-cb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-eb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-cb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-eb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-jb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-nb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-el-tb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-jb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-nb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610-tb:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dea:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dna:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:wise-6610p-dta:*:*:*:*:*:*:*:*
Vendors & Products Advantech
Advantech wise-6610-cb
Advantech wise-6610-eb
Advantech wise-6610-el-cb
Advantech wise-6610-el-eb
Advantech wise-6610-el-jb
Advantech wise-6610-el-nb
Advantech wise-6610-el-tb
Advantech wise-6610-jb
Advantech wise-6610-nb
Advantech wise-6610-tb
Advantech wise-6610p-dea
Advantech wise-6610p-dna
Advantech wise-6610p-dta
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Advantech Wise-6610 Wise-6610-cb Wise-6610-eb Wise-6610-el-cb Wise-6610-el-eb Wise-6610-el-jb Wise-6610-el-nb Wise-6610-el-tb Wise-6610-jb Wise-6610-nb Wise-6610-tb Wise-6610p-dea Wise-6610p-dna Wise-6610p-dta
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:35:36.242Z

Reserved: 2026-08-25T12:13:42.095Z

Link: CVE-2026-79698

cve-icon Vulnrichment

Updated: 2026-09-11T20:15:47.486Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T07:16:47.420

Modified: 2026-09-11T21:17:17.030

Link: CVE-2026-79698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T00:15:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')