Junglewise Threat Intelligence

CVE-2026-43829: Advantech ADAM-3600 EdgeLink stack buffer overflow in password functionality

CVE-2026-43829 · Severity: info · CVSS 9.2 · Published 2026-07-31

Executive brief

Advantech ADAM-3600 EdgeLink, a gateway device used in industrial automation to connect field equipment to the cloud, contains a critical security flaw. An unauthenticated attacker can exploit a weakness in the password handling system to take full control of the device. This could lead to unauthorized access to industrial processes, data theft, or disruption of operations.

Technical details

A stack-based buffer overflow exists in the password processing logic of Advantech ADAM-3600 EdgeLink. The vulnerability is triggered when the 'SafeEnhancement' feature is enabled and can be exploited by an unauthenticated attacker via the network. Successful exploitation allows for remote code execution (RCE) on the device. The issue is addressed in version 2.8.5.1 and later. The CVSS 4.0 score of 9.2 reflects high impact on confidentiality, integrity, and availability, though the attack complexity is rated as high.

Affected products

  • Advantech ADAM-3600 EdgeLink prior to version 2.8.5.1

Timeline

  • 2026-07-31: advisory: NVD publication date
  • 2026-07-31: disclosed: Initial disclosure by CSA Singapore

References

Related threats