Advantech WebAccess/VPN versions prior to 1.1.5 contain a...
Moderate severity
Unreviewed
Published
Nov 6, 2025
to the GitHub Advisory Database
•
Updated Nov 28, 2025
Description
Published by the National Vulnerability Database
Nov 6, 2025
Published to the GitHub Advisory Database
Nov 6, 2025
Last updated
Nov 28, 2025
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
References