Executive brief
The iVEC-IEI Virtualization Edge Computer, an industrial computing platform used for edge virtualization, contains a security flaw that allows authenticated users to delete system files. An attacker with basic login credentials could remotely delete critical data or system directories, potentially causing permanent data loss or rendering the device inoperable. This could disrupt industrial operations or services relying on the edge computer.
Technical details
An arbitrary file deletion vulnerability exists in the IEI Integration Corp iVEC-IEI Virtualization Edge Computer (specifically the TANK-XM811 model) due to improper limitation of a pathname to a restricted directory (CWE-22). A remote attacker with low-level authentication (PR:L) can exploit this path traversal flaw to target and delete arbitrary files or directories across the system. Successful exploitation can lead to a complete loss of integrity for system data and a total loss of availability if critical system components are removed. The vulnerability is addressed in version v1.0.4.
Affected products
- IEI Integration Corp iVEC TANK-XM811 before v1.0.4
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2026-06-12: patched: Fixed in version v1.0.4