SecBoard
Zurück zur CVE-Übersicht

CVE-2026-79698

CRITICAL(9.9)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Risk Signal Score30/100 — MITTEL
  • CVSS 9.9 — Kritisch

EPSS-Score

1.7%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.9

Technische Schwere

SecBoard-Einordnung

Security-Teams sollten umgehend alle betroffenen Advantech WISE-6610 und WISE-6610P Geräte auf die Version 1.2.4_20260821 oder höher aktualisieren. Angesichts der Kritikalität und der öffentlichen Verfügbarkeit eines Exploits ist dies eine hochprioritäre Maßnahme, um das Risiko einer Kompromittierung zu minimieren.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

In diesen Analysen erwähnt

Referenzen