Junglewise Threat Intelligence

CVE-2026-43831: Advantech ADAM-3600 EdgeLink stack overflow in log message functionality

CVE-2026-43831 · Severity: info · CVSS 9.2 · Published 2026-07-31

Executive brief

Advantech ADAM-3600 EdgeLink is an industrial computing platform used for remote monitoring and data management in infrastructure and utility sectors. A vulnerability in its logging system could allow an unauthorized attacker to remotely take control of the device. This could lead to service disruptions, unauthorized access to industrial data, or the ability to manipulate connected equipment.

Technical details

A stack-based buffer overflow vulnerability exists within the log message functionality of Advantech ADAM-3600 EdgeLink. The flaw is triggered by improper handling of input data during logging operations, which can be exploited by an unauthenticated attacker over the network. Successful exploitation allows for arbitrary code execution with high privileges on the underlying system. The vulnerability is addressed in version 2.8.5.1 and later. While the attack complexity is rated as high in the CVSS vector, no user interaction is required.

Affected products

  • Advantech ADAM-3600 EdgeLink prior to version 2.8.5.1

Timeline

  • 2026-07-31: advisory: Advisory published by CSA and NVD

References

Related threats