Executive brief
Advantech WISE-6610 industrial control devices are used in factory and process automation environments to manage network connectivity and data collection. A command injection vulnerability in the certificate deletion handler allows remote attackers to execute arbitrary system commands on affected devices, potentially enabling unauthorized access to critical industrial operations and sensitive manufacturing data.
Technical details
A command injection vulnerability exists in the basicstation_apply function of the Basic Station Certificate-Deletion Handler component in Advantech WISE-6610 devices. The vulnerability is triggered by improper sanitization of the "act" argument, allowing an attacker to inject shell commands that are executed with device privileges. The attack is remotely exploitable and requires no authentication. A successful exploit grants the attacker arbitrary code execution on the affected industrial device. The vulnerability has been patched in firmware version 1.2.4_20260821 and later; users should upgrade immediately.
Affected products
- Advantech WISE-6610-NB 1.2.1_20251110
- Advantech WISE-6610-EB 1.2.1_20251110
- Advantech WISE-6610-TB 1.2.1_20251110
- Advantech WISE-6610-JB 1.2.1_20251110
- Advantech WISE-6610-CB 1.2.1_20251110
- Advantech WISE-6610-EL-NB 1.2.1_20251110
- Advantech WISE-6610-EL-EB 1.2.1_20251110
- Advantech WISE-6610-EL-TB 1.2.1_20251110
- Advantech WISE-6610-EL-JB 1.2.1_20251110
- Advantech WISE-6610-EL-CB 1.2.1_20251110
- Advantech WISE-6610P-DEA 1.2.1_20251110
- Advantech WISE-6610P-DNA 1.2.1_20251110
- Advantech WISE-6610P-DTA 1.2.1_20251110
Timeline
- 2026-09-07: disclosed
- 2026-08-21: patched: Fixed in firmware version 1.2.4_20260821