CVE-2025-62630

8.8

Advantech · DeviceOn/iEdge

A directory traversal vulnerability in Advantech DeviceOn/iEdge allows authenticated attackers to upload malicious configuration files, leading to remote code execution with system-level privileges.

Executive summary

A critical directory traversal vulnerability in Advantech DeviceOn and iEdge software allows authenticated attackers to achieve remote code execution with system-level permissions.

Vulnerability

The flaw is a directory traversal vulnerability (CWE-22) triggered by the insufficient sanitization of configuration files during upload. An attacker with low-level authenticated access can manipulate file paths to execute arbitrary code with system-level permissions.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected device with system-level permissions. This level of access poses a severe risk to operational technology environments, potentially leading to unauthorized system manipulation, total loss of data confidentiality and integrity, and significant operational downtime. With a CVSS score of 8.8, this vulnerability is considered High severity and requires immediate attention to prevent system compromise.

Remediation

Immediate Action: Advantech has classified these products as end-of-life and recommends that all users migrate their systems to the current DeviceOn platform, which is not affected by this vulnerability.

Proactive Monitoring: Security teams should monitor network traffic for anomalous file upload activity and review system logs for unauthorized configuration changes or unexpected process execution.

Compensating Controls: If immediate migration is not feasible, restrict network access to the affected devices using firewall rules to ensure only trusted administrative endpoints can reach the management interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the end-of-life status of the affected products, patching is not an option. Organizations must prioritize the migration to the current DeviceOn platform as the primary method to eliminate this risk. Until migration is complete, isolating the affected systems from the wider corporate network is essential to prevent potential exploitation.

More Advantech CVEs

Sources

Originally found and disclosed by Alex Williams of Pellera Technologies reported this vulnerability to CISA., per the CVE Program record.