Executive brief
Advantech ADAM-3600 EdgeLink is an industrial computing platform used to manage data between field devices and the cloud. A security vulnerability in how the device handles web cookies could allow an unauthorized person to remotely take control of the system. This could lead to unauthorized access to industrial data, disruption of operations, or complete system takeover if the SafeEnhancement feature is active.
Technical details
A stack-based buffer overflow vulnerability exists in the Cookie parsing methods of Advantech ADAM-3600 EdgeLink. The flaw is triggered when the 'SafeEnhancement' feature is enabled and the system processes specially crafted HTTP cookies. An unauthenticated remote attacker can exploit this by sending malicious requests to the device's web interface, potentially leading to arbitrary code execution with high privileges. The vulnerability is addressed in version 2.8.5.1 and later. The attack complexity is rated as high, likely due to specific configuration requirements or memory protection mechanisms.
Affected products
- Advantech ADAM-3600 EdgeLink prior to version 2.8.5.1
Timeline
- 2026-07-31: advisory: NVD publication date
- 2026-07-31: patched: Fix available in version 2.8.5.1