CVE-2026-79697
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
- EPSS probability
- 3.35%
- CWE
- CWE-77, CWE-74
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- Advantech WISE-6610-NB
- Advantech WISE-6610-NB
- Advantech WISE-6610-EB
- Advantech WISE-6610-EB
- Advantech WISE-6610-TB
- Advantech WISE-6610-TB
- Advantech WISE-6610-JB
- Advantech WISE-6610-JB
Weakness type
Related vulnerabilities
- CVE-2026-83948 — Microsoft Azure CLI Remote Code Execution Vulnerability
- CVE-2026-81380 — GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
- CVE-2026-69534 — Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
- CVE-2026-84387 — A improper neutralization of special elements used in a command ('command injection') vulnerability...
- CVE-2026-86427 — LibreNMS before 26.8.0 Argument Injection via graph_title
- CVE-2026-86299 — Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection
- CVE-2026-86295 — D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection
- CVE-2026-79698 — Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection