Junglewise Threat Intelligence

CVE-2026-6889: Advantech ECU-1251D denial of service in DNP3Daemon

CVE-2026-6889 · Severity: info · CVSS 6.9 · Published 2026-07-31

Executive brief

A denial of service vulnerability exists in the Advantech ECU-1251D, an industrial communication gateway used in power and automation sectors. An attacker on the same local network can send a specific signal that causes the device's communication service to crash and enter an infinite restart loop. This prevents operators from monitoring or controlling the device via SCADA systems until it is manually restarted on-site.

Technical details

A denial of service (DoS) vulnerability exists in the DNP3Daemon component of the Advantech ECU-1251D industrial gateway. The flaw is triggered when a network-adjacent attacker sends a DNP3 signal to the Digital Output address of the device. This causes the daemon to attempt to invoke a non-existent system file, resulting in an indefinite restart loop. While the web management panel remains partially accessible, SCADA TelWin operators lose the ability to reconnect to the device. The vulnerability is addressed in EdgeLink version 2.8.5.0 and later.

Affected products

  • Advantech ECU-1251D EdgeLink versions prior to 2.8.5.0

Timeline

  • 2026-07-30: disclosed: CVE record published by CSA Singapore
  • 2026-07-31: advisory: NVD entry and CSA Singapore alert published

References

Related threats