CVE-2026-79697

9.9

Advantech · WISE-6610 series

A command injection vulnerability in the basicstation_apply function of Advantech WISE-6610 series gateways allows remote attackers to execute arbitrary commands via the act argument.

Executive summary

A critical command injection vulnerability in Advantech WISE-6610 series gateways allows authenticated remote attackers to achieve full system compromise.

Vulnerability

The flaw exists within the Basic Station Certificate-Deletion Handler component, specifically the basicstation_apply function. By manipulating the act argument, a remote attacker with low privileges can perform command injection, leading to unauthorized code execution on the underlying operating system.

Business impact

The ability to execute arbitrary commands remotely poses a catastrophic risk to industrial infrastructure. Successful exploitation results in complete loss of confidentiality, integrity, and availability, as attackers can gain full control over the gateway, pivot into internal networks, or disrupt critical industrial processes. Given the critical CVSS score of 9.9, this vulnerability represents an immediate threat to operational continuity and data security.

Remediation

Immediate Action: Upgrade firmware to version 1.2.4_20260821 or higher, as provided by Advantech, to patch the vulnerable function.

Proactive Monitoring: Monitor network traffic for suspicious outbound connections from the gateway and review system logs for unauthorized command execution attempts or unexpected process spawns.

Compensating Controls: Restrict access to the management interface to trusted administrative IP addresses only, and employ a Web Application Firewall or similar inspection tool to filter malicious payloads targeting the act argument.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up provided by the vulnerability researcher.

Analyst recommendation

Due to the critical severity and the public availability of technical details, organizations using the affected Advantech WISE-6610 hardware must prioritize patching immediately. The ease of remote command injection mandates that all vulnerable gateways be updated to firmware version 1.2.4_20260821 without delay to prevent potential unauthorized access and system takeover.

More Advantech CVEs all →

Sources

Originally found and disclosed by hubdk01 (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.