Junglewise Threat Intelligence

CVE-2026-43833: Advantech ADAM-3600 EdgeLink stack overflow in upload functionality

CVE-2026-43833 · Severity: info · CVSS 7.5 · Published 2026-07-31

Executive brief

Advantech ADAM-3600 EdgeLink, an industrial gateway used for remote monitoring and data collection, is affected by a security vulnerability in its file upload feature. An authenticated attacker with high privileges could exploit this flaw to crash the system or execute unauthorized code. This could lead to a complete loss of control over the device, potentially disrupting industrial operations or exposing sensitive operational data.

Technical details

A stack-based buffer overflow vulnerability exists in the upload functionality of Advantech ADAM-3600 EdgeLink. The flaw is triggered when the application fails to properly validate the length of input data during file upload operations. An authenticated attacker with high privileges can exploit this by sending a specially crafted request to the device over the network. Successful exploitation allows for arbitrary code execution on the underlying operating system. The vulnerability is addressed in version 2.8.5.1 and later.

Affected products

  • Advantech ADAM-3600 EdgeLink prior to version 2.8.5.1

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: advisory

References

Related threats