CVE-2025-58423

8.8

Advantech · DeviceOn/iEdge

A path traversal vulnerability in Advantech DeviceOn/iEdge allows authenticated attackers to perform file read/write operations or cause a denial-of-service via crafted configuration files.

Executive summary

A critical path traversal vulnerability in Advantech DeviceOn and iEdge products allows authenticated attackers to execute arbitrary file operations or disrupt service with system-level privileges.

Vulnerability

This vulnerability, classified as CWE-22, occurs due to insufficient input sanitization during the processing of configuration files, allowing an authenticated user to perform directory traversal and unauthorized file system manipulation.

Business impact

The ability to read or write files within the context of the local system account presents a severe risk of unauthorized data access and potential system compromise. Given the CVSS score of 8.8, this vulnerability carries a high risk of total loss of confidentiality, integrity, and availability for the affected device, potentially leading to operational downtime or the exfiltration of sensitive configuration data.

Remediation

Immediate Action: As the affected products are end-of-life, users must transition to the current Advantech DeviceOn platform, which is not susceptible to this vulnerability.

Proactive Monitoring: Monitor system logs for unusual file access patterns or unexpected configuration upload attempts that deviate from standard administrative workflows.

Compensating Controls: Restrict access to the management interface to authorized personnel only, and implement network segmentation to isolate the affected devices from untrusted network segments.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this issue is compounded by the end-of-life status of the affected software, which precludes the availability of security patches. Organizations currently utilizing Advantech DeviceOn or iEdge versions 2.0.2 and below should prioritize an immediate migration to the supported DeviceOn platform to eliminate this security risk.

More Advantech CVEs

Sources

Originally found and disclosed by Alex Williams of Pellera Technologies reported this vulnerability to CISA., per the CVE Program record.