Advantech WebAccess Node
Multiple vulnerabilities in Advantech WebAccessNode (input validation, buffer overflows, SQL injection) allow unauthenticated remote code execution, information disclosure, and denial of service. Affected versions: 8.4.4 and earlier, 9.0.0. Attacker can send crafted requests over the network without authentication to execute arbitrary code on the device. Vendor has released patch versions 8.4.4.P0320844 and 9.0.0.P0320900 to address the issues. No public exploits are currently known, but the vulnerability has high exploit probability (EPSS 31.4%).
- Network access to WebAccess Node (port/service dependent on deployment)
- No authentication required
- Ability to send HTTP/network traffic to the device
Patching may require device reboot — plan for process interruption
/api/v1/advisories/01450735-b7af-4289-ad1a-d63cf56eba96Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.