Junglewise Threat Intelligence

CVE-2026-6890: Advantech ECU-1251D use of default credentials in SSH root account

CVE-2026-6890 · Severity: info · CVSS 7.1 · Published 2026-07-31

Executive brief

The Advantech ECU-1251D, an industrial communication gateway used to connect field devices to networks, contains a security flaw where it ships with a default 'root' account that has no password. If an attacker has access to the local network, they can log into the device via SSH and gain full administrative control. This could lead to unauthorized monitoring of industrial processes or a complete takeover of the gateway, potentially disrupting operations.

Technical details

The Advantech ECU-1251D industrial communication gateway suffers from a use of default credentials vulnerability. The device manual documents a default 'root' account with no password for SSH access, and the system does not prompt or require users to change these credentials during initial configuration. An attacker with network access to the device (specifically the SSH service) can gain full root-level shell access. This vulnerability affects ECU-1251D products running EdgeLink versions prior to 2.8.5.0. Advantech has released a security update to address this issue.

Affected products

  • Advantech ECU-1251D (EdgeLink) prior to 2.8.5.0

Timeline

  • 2026-07-31: advisory: Advisory published by the Cyber Security Agency of Singapore (CSA)
  • 2026-07-31: patched: Advantech released EdgeLink version 2.8.5.0 to address the issue.

References

Related threats