PT-2025-45356 · Advantech · Webaccess/Vpn

·

CVE-2025-34239

·

Published

2025-10-31

·

Updated

2025-11-07

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess/VPN versions prior to 1.1.5
Description The software contains a command injection issue in the AppManagementController.appUpgradeAction() function. A system administrator with authentication can execute arbitrary commands as the web server user (www-data) by providing a specially crafted filename during an upload process.
Recommendations Update to version 1.1.5 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13988
CVE-2025-34239

Affected Products

Webaccess/Vpn