Junglewise Threat Intelligence

CVE-2026-2670: Advantech WISE-6610 OS command injection in OpenVPN management

CVE-2026-2670 · Severity: high · CVSS 7.2 · Published 2026-02-18

Technologies: Advantech WISE-6610-EL-JB, Advantech WISE-6610-EL-CB, Advantech WISE-6610-JB, Advantech WISE-6610-TB, Advantech WISE-6610-NB, Advantech WISE-6610P-DNA, Advantech WISE-6610P-DEA, Advantech WISE-6610-EB, Advantech WISE-6610-EL-NB, Advantech WISE-6610-CB, Advantech WISE-6610-EL-EB, Advantech WISE-6610P-DTA, Advantech WISE-6610-EL-TB. Vendors: Advantech.

Executive brief

Advantech WISE-6610 is an industrial IoT gateway used to manage networks and remote access. A vulnerability in its web-based management interface allows an attacker to inject and execute arbitrary system commands with root privileges by manipulating file deletion requests, potentially giving complete control over the device.

Technical details

The vulnerability is an OS command injection flaw in the /cgi-bin/luci/admin/openvpn_apply endpoint of the Background Management component. The vulnerable code constructs a shell command from user-supplied input (the delete_file parameter) without proper sanitization, then executes it via os.execute(). An authenticated attacker can send a crafted POST request with malicious shell metacharacters in the delete_file argument to achieve arbitrary command execution as root. The attack is network-accessible and requires valid authentication. The vendor patched the issue in version 1.2.4_20260821 by redesigning the delete operation to use an allowlist of file paths, require numeric tunnel IDs, and use the native filesystem API instead of shell command construction.

Affected products

  • Advantech WISE-6610-NB 1.2.1_20251110
  • Advantech WISE-6610-EB 1.2.1_20251110
  • Advantech WISE-6610-TB 1.2.1_20251110
  • Advantech WISE-6610-JB 1.2.1_20251110
  • Advantech WISE-6610-CB 1.2.1_20251110
  • Advantech WISE-6610-EL-NB 1.2.1_20251110
  • Advantech WISE-6610-EL-EB 1.2.1_20251110
  • Advantech WISE-6610-EL-TB 1.2.1_20251110
  • Advantech WISE-6610-EL-JB 1.2.1_20251110
  • Advantech WISE-6610-EL-CB 1.2.1_20251110
  • Advantech WISE-6610P-DEA 1.2.1_20251110
  • Advantech WISE-6610P-DNA 1.2.1_20251110
  • Advantech WISE-6610P-DTA 1.2.1_20251110

Timeline

  • 2026-02-18: disclosed
  • 2026-02-18: patched: Patch available in firmware version 1.2.4_20260821

References

Related threats