Junglewise Threat Intelligence

CVE-2026-79698: Advantech WISE-6610 command injection in Node-RED Library

CVE-2026-79698 · Severity: critical · CVSS 9.9 · Published 2026-09-07

Technologies: Advantech WISE-6610P-DTA, Advantech WISE-6610P-DEA, Advantech WISE-6610-TB, Advantech WISE-6610-EL-TB, Advantech WISE-6610P-DNA, Advantech WISE-6610-EL-EB, Advantech WISE-6610-EL-JB, Advantech WISE-6610-EL-CB, Advantech WISE-6610-EL-NB, Advantech WISE-6610-JB, Advantech WISE-6610-NB, Advantech WISE-6610-EB, Advantech WISE-6610-CB. Vendors: Advantech.

Executive brief

Advantech WISE-6610 is an industrial IoT gateway widely used in manufacturing and critical infrastructure to collect and process sensor data. A remote command injection vulnerability in its Node-RED Library component allows attackers to execute arbitrary system commands without authentication, potentially gaining full control of the device and compromising connected networks and systems.

Technical details

A command injection vulnerability exists in the nodered_lib_apply function of the Node-RED Library component in affected Advantech WISE-6610 devices. The vulnerability is caused by insufficient input validation of the "act" argument, which allows an attacker to inject arbitrary shell commands. The attack is remotely exploitable without requiring authentication. An attacker can achieve remote code execution (RCE) with the privileges of the device's application process. The vulnerability affects versions prior to 1.2.4_20260821; upgrading to this version or later resolves the issue.

Affected products

  • Advantech WISE-6610-NB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-EB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-TB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-JB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-CB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-EL-NB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-EL-EB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-EL-TB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-EL-JB 1.2.1_20251110 and earlier
  • Advantech WISE-6610-EL-CB 1.2.1_20251110 and earlier
  • Advantech WISE-6610P-DEA 1.2.1_20251110 and earlier
  • Advantech WISE-6610P-DNA 1.2.1_20251110 and earlier
  • Advantech WISE-6610P-DTA 1.2.1_20251110 and earlier

Timeline

  • 2026-09-07: disclosed: Vulnerability publicly disclosed via NVD
  • 2026-08-21: patched: Fixed version 1.2.4_20260821 released by vendor

References

Related threats