Advantech WebAccess/VPN versions prior to 1.1.5 contain a...
High severity
Unreviewed
Published
Nov 6, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Nov 6, 2025
Published to the GitHub Advisory Database
Nov 6, 2025
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.
References