Executive brief
The iVEC-IEI Virtualization Edge Computer, an industrial computing device used for edge processing and virtualization, contains a security flaw that allows an authorized user with high-level privileges to execute unauthorized system commands. If exploited, an attacker could take full control of the device, potentially leading to data theft, service disruption, or unauthorized access to the local network. This vulnerability requires the attacker to already have administrative credentials.
Technical details
An OS command injection vulnerability (CWE-78) exists in the IEI Integration Corp iVEC TANK-XM811 virtualization edge computer. The flaw allows a remote attacker with high privileges (administrative access) to inject and execute arbitrary operating system commands on the underlying host. The attack is carried out over the network without requiring user interaction. Successful exploitation grants the attacker full system-level control, enabling them to read, modify, or delete any data and potentially pivot to other systems on the network. The vulnerability is addressed in version v1.0.4.
Affected products
- IEI Integration Corp iVEC TANK-XM811 before v1.0.4
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2026-06-12: patched: Update to v1.0.4 or later