Junglewise Threat Intelligence

CVE-2026-43830: Advantech ADAM-3600 EdgeLink command injection in firmware upgrade

CVE-2026-43830 · Severity: info · CVSS 8.6 · Published 2026-07-31

Executive brief

Advantech ADAM-3600 EdgeLink is an industrial gateway used to connect field devices to cloud services. A security flaw in the firmware update process allows an attacker with administrative access to take full control of the device by injecting malicious commands. This could lead to unauthorized operational changes, data theft, or complete disruption of industrial monitoring systems.

Technical details

A command injection vulnerability exists in the firmware upgrade file verification process of Advantech ADAM-3600 EdgeLink. The flaw is triggered when the system processes a specially crafted firmware file, failing to properly sanitize inputs before execution. An attacker with high privileges (PR:H) can exploit this over the network to execute arbitrary system commands with the permissions of the update process. This can lead to a complete compromise of the device's integrity and availability. The vulnerability is addressed in version 2.8.5.1 and later.

Affected products

  • Advantech ADAM-3600 EdgeLink prior to version 2.8.5.1

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: advisory

References

Related threats