PT-2025-45356 · Advantech · Webaccess/Vpn

Alex Williams

·

Published

2025-10-31

·

Updated

2025-11-07

·

CVE-2025-34239

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess/VPN versions prior to 1.1.5
Description The software contains a command injection issue in the AppManagementController.appUpgradeAction() function. A system administrator with authentication can execute arbitrary commands as the web server user (www-data) by providing a specially crafted filename during an upload process.
Recommendations Update to version 1.1.5 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-13988
CVE-2025-34239

Affected Products

Webaccess/Vpn