Executive brief
A vulnerability exists in several Advantech IoT and SCADA management products, which are used to monitor and control industrial systems and smart infrastructure. An attacker with administrative credentials could exploit this flaw to run unauthorized commands on the system. This could lead to the theft, modification, or deletion of sensitive operational data and potentially disrupt industrial processes.
Technical details
A SQL injection vulnerability (CWE-89) exists within a specific interface of several Advantech products, including SaaS Composer, IoTSuite, and WebAccess/SCADA. The flaw stems from improper neutralization of special elements used in SQL commands. A remote attacker with high privileges (PR:H) can exploit this vulnerability over the network without user interaction. Successful exploitation allows for arbitrary command execution and the ability to access, modify, or delete sensitive information within the underlying database. Advantech has released security updates for all affected products; some updates require a full reinstallation of the software.
Affected products
- Advantech SaaS Composer prior to 3.4.17
- Advantech IoTSuite Growth Linux docker prior to 2.2.0
- Advantech IoTSuite Starter Linux docker prior to 2.2.0
- Advantech IoT Edge Linux docker prior to 2.2.0
- Advantech IoT Edge Windows prior to 2.2.0
- Advantech WebAccess/SCADA prior to 9.2.3
- Advantech WebAccess SaaS-Composer prior to 3.4.17.1
- Advantech ECOWatch SaaS-Composer prior to 3.4.17
Timeline
- 2026-05-13: disclosed: Advisory published by CSA Singapore and NVD
- 2026-05-13: patched: Advantech released security updates for affected versions