CVE-2025-14849
8.8Advantech · WebAccess/SCADA
Advantech WebAccess/SCADA contains an unrestricted file upload vulnerability that may allow a remote, authenticated attacker to execute arbitrary code on the affected system.
Executive summary
A critical unrestricted file upload vulnerability in Advantech WebAccess/SCADA allows authenticated attackers to execute arbitrary code, posing a significant risk to industrial control environments.
Vulnerability
The application is susceptible to an unrestricted file upload flaw (CWE-434), which enables an attacker with authenticated access to upload and execute malicious files. According to the CVSS vector, this requires low privileges to exploit, but it does not require user interaction to trigger remote code execution.
Business impact
Successful exploitation of this vulnerability can lead to a full compromise of the SCADA environment, resulting in unauthorized control of industrial processes, data theft, or complete system downtime. With a CVSS score of 8.8, this vulnerability is classified as High severity. Given the nature of SCADA systems, the potential for operational disruption and physical safety implications makes remediation a top priority for facility security teams.
Remediation
Immediate Action: Update Advantech WebAccess/SCADA to version 9.2.2 or later as specified by the vendor advisory.
Proactive Monitoring: Monitor system logs for unusual file creation events in web directories and audit user activity for suspicious account behavior.
Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect and block unauthorized file uploads and restrict access to the WebAccess/SCADA interface to trusted internal networks only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk posed by arbitrary code execution in a SCADA environment is extreme. Administrators should prioritize patching to version 9.2.2 immediately to eliminate the underlying vulnerability. Organizations unable to patch immediately must implement strict network segmentation and WAF rules to prevent unauthorized access to the application and restrict the ability to upload files to the server.
More Advantech CVEs
Sources
Originally found and disclosed by Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA., per the CVE Program record.