CVE-2025-59171

7.5

Advantech · DeviceOn/iEdge

Advantech DeviceOn/iEdge versions 0 through 2.0.2 are vulnerable to path traversal via malicious configuration file uploads, potentially leading to remote code execution with system-level privileges.

Executive summary

Unauthenticated attackers can achieve remote code execution on Advantech DeviceOn and iEdge devices by exploiting a path traversal vulnerability during configuration file uploads.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) caused by insufficient sanitization of configuration files. An unauthenticated attacker can exploit this to achieve remote code execution with system-level permissions.

Business impact

The potential for remote code execution with system-level privileges presents a critical risk to operational technology environments. Successful exploitation allows for complete compromise of the affected device, potentially leading to unauthorized control of industrial processes, loss of data integrity, and significant system downtime. With a CVSS score of 7.5, this high-severity vulnerability requires immediate attention to prevent unauthorized access to critical infrastructure components.

Remediation

Immediate Action: Because the affected products have reached end-of-life status, users must migrate to the current DeviceOn platform, which is not affected by this vulnerability. Contact Advantech support directly for migration assistance and upgrade paths.

Proactive Monitoring: Review device access logs for unusual file upload activity or unauthorized configuration changes. Monitor network traffic for anomalous connections originating from or directed toward these devices.

Compensating Controls: Deploy a Web Application Firewall (WAF) or industrial firewall to restrict access to the device management interface. Isolate these devices within a segmented network to limit the potential reach of an attacker.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given that these devices are end-of-life and no patch will be issued, the primary mitigation is immediate decommissioning and migration to supported software. The high risk of remote code execution necessitates that these devices be removed from public-facing networks or isolated immediately until the migration process is complete. Failure to address this vulnerability exposes the environment to significant risk of unauthorized system control.

More Advantech CVEs

Sources

Originally found and disclosed by Alex Williams of Pellera Technologies reported this vulnerability to CISA., per the CVE Program record.