CVE-2026-6889
Received Received - Intake

Denial of Service in Advantech ECU-1251D via DNP3 Signal

Vulnerability report for CVE-2026-6889, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: CSA

Description

A denial of service vulnerability in the Advantech ECU-1251D allows a network-adjacent attacker to send a DNP3 signal to the Digital Output address of the device, causing the DNP3Daemon to invoke a non-existent system file and enter an indefinite restart loop. While the device remains partially accessible via its web panel or direct signals, an operator using SCADA TelWin is unable to reconnect until the device is manually restarted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
advantech ecu-1251d *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in the Advantech ECU-1251D device. A network-adjacent attacker can send a DNP3 signal to the Digital Output address, causing the DNP3Daemon to attempt accessing a non-existent system file. This triggers an indefinite restart loop, making the device partially accessible but preventing SCADA TelWin reconnection until manually restarted.

Detection Guidance

Monitor for repeated DNP3 signals targeting Digital Output addresses on Advantech ECU-1251D devices. Check for system file invocation errors in device logs and unexpected restart loops. Use network traffic analysis tools to detect anomalous DNP3 traffic patterns.

Impact Analysis

The vulnerability disrupts device operations by causing continuous restarts, leading to temporary loss of functionality. Operators may be unable to reconnect via SCADA TelWin, requiring manual intervention. While the web panel or direct signals may still work, the device's reliability and availability are compromised.

Mitigation Strategies

Isolate affected devices from untrusted networks. Apply vendor patches if available. Restrict DNP3 traffic to trusted sources only. Monitor device logs for restart loops and manually restart devices if necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6889. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart