CVE-2026-79697
CRITICAL(9.9)CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CVSS 9.9 — Kritisch
EPSS-Score
3.4%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.9
Technische Schwere
SecBoard-Einordnung
Security-Teams sollten umgehend die betroffenen Advantech WISE-6610 und WISE-6610P Geräte auf Version 1.2.4_20260821 aktualisieren, um diese Schwachstelle zu beheben. Angesichts der Kritikalität und der öffentlichen Verfügbarkeit eines Exploits ist eine schnelle Patch-Implementierung dringend erforderlich, um potenzielle Angriffe zu verhindern.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
In diesen Analysen erwähnt
Referenzen
- https://uvxbywu62qm.feishu.cn/wiki/EzwXwS0vKiroHmk9rqzcjP0EnMe?from=from_copylin...
- https://vuldb.com/cve/CVE-2026-79697
- https://vuldb.com/submit/879208
- https://vuldb.com/vuln/399512
- https://vuldb.com/vuln/399512/cti
- https://www.advantech.com/
- https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI
- https://www.advantech.com/zh-tw/security-advisory