Impact
A flaw in the advanced node functionalities of the Node‑RED library allows an attacker to craft a malicious "act" argument that is passed directly to the system shell, enabling arbitrary command execution from a remote source. The weakness is classified under CWE‑74 and CWE‑77, both of which represent improper handling of input that can lead to OS command injection. With a CVSS score of 9.4, the vulnerability grants full control over the affected device, jeopardizing confidentiality, integrity, and availability of the system and potentially all devices on the same network.
Affected Systems
The issue affects Advantech WISE‑6610 devices—including the CB, EB, EL‑NB, EL‑EB, EL‑TB, EL‑JB, NB, TB, JB variants and the three P‑series models (P‑DEA, P‑DNA, P‑DTA)—running firmware version 1.2.1_20251110 or earlier. All listed models are vulnerable when the Node‑RED library is present and the exploitable endpoint is accessible.
Risk and Exploitability
The vulnerability is remotely exploitable without requiring prior authentication; it relies on network access to the Node‑RED server exposed by the device. The EPSS score is 0.03 (3%), indicating a low but non‑zero probability of exploitation, and the public availability of an exploit combined with the high CVSS base score suggest a strong likelihood of real‑world attacks. The vulnerability is not currently listed in CISA’s KEV catalog, but the risk remains high for systems that remain on affected firmware versions.
OpenCVE Enrichment