Executive brief
Advantech Hospital Queuing Management, a system used to manage patient flow and appointments in healthcare facilities, contains a critical security flaw. An unauthorized person can remotely access the system's internal programming interfaces to steal sensitive hospital data or create their own administrator accounts. This could lead to a total takeover of the system, compromising patient privacy and disrupting hospital operations.
Technical details
A missing authentication vulnerability (CWE-306) exists in Advantech Hospital Queuing Management (HQM) prior to version 1.2.13. The flaw resides in the system's API handling, where certain critical functions do not require identity verification. An unauthenticated remote attacker can exploit this by sending crafted requests to specific API endpoints to extract sensitive data or register new administrative users. The vulnerability is addressed by updating the HQM ISO to version 1.2.13 or later, or by specifically updating the QueueHttp.dll component to version 1.2.12.7 or later.
Affected products
- Advantech Hospital Queuing Management (HQM) ISO before 1.2.13
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory