CVE-2026-79697
Received Received - Intake

Command Injection in Advantech WISE-6610 Series

Vulnerability report for CVE-2026-79697, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: VulDB

Description

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 39 associated CPEs
Vendor Product Version / Range
advantech wise-6610-nb 1.2.1_20251110
advantech wise-6610-eb 1.2.1_20251110
advantech wise-6610-tb 1.2.1_20251110
advantech wise-6610-jb 1.2.1_20251110
advantech wise-6610-cb 1.2.1_20251110
advantech wise-6610-el-nb 1.2.1_20251110
advantech wise-6610-el-eb 1.2.1_20251110
advantech wise-6610-el-tb 1.2.1_20251110
advantech wise-6610-el-jb 1.2.1_20251110
advantech wise-6610-el-cb 1.2.1_20251110
advantech wise-6610p-dea 1.2.1_20251110
advantech wise-6610p-dna 1.2.1_20251110
advantech wise-6610p-dta 1.2.1_20251110
advantech wise-6610-nb From 1.2.4_20260821 (inc)
advantech wise-6610-eb From 1.2.4_20260821 (inc)
advantech wise-6610-tb From 1.2.4_20260821 (inc)
advantech wise-6610-jb From 1.2.4_20260821 (inc)
advantech wise-6610-cb From 1.2.4_20260821 (inc)
advantech wise-6610-el-nb From 1.2.4_20260821 (inc)
advantech wise-6610-el-eb From 1.2.4_20260821 (inc)
advantech wise-6610-el-tb From 1.2.4_20260821 (inc)
advantech wise-6610-el-jb From 1.2.4_20260821 (inc)
advantech wise-6610-el-cb From 1.2.4_20260821 (inc)
advantech wise-6610p-dea From 1.2.4_20260821 (inc)
advantech wise-6610p-dna From 1.2.4_20260821 (inc)
advantech wise-6610p-dta From 1.2.4_20260821 (inc)
advantech wise-6610-nb 1.2.4_20260821
advantech wise-6610-eb 1.2.4_20260821
advantech wise-6610-tb 1.2.4_20260821
advantech wise-6610-jb 1.2.4_20260821
advantech wise-6610-cb 1.2.4_20260821
advantech wise-6610-el-nb 1.2.4_20260821
advantech wise-6610-el-eb 1.2.4_20260821
advantech wise-6610-el-tb 1.2.4_20260821
advantech wise-6610-el-jb 1.2.4_20260821
advantech wise-6610-el-cb 1.2.4_20260821
advantech wise-6610p-dea 1.2.4_20260821
advantech wise-6610p-dna 1.2.4_20260821
advantech wise-6610p-dta 1.2.4_20260821

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a command injection flaw in Advantech WISE-6610 series devices running version 1.2.1_20251110. It exists in the Basic Station Certificate-Deletion Handler component, specifically in the basicstation_apply function where manipulation of the 'act' argument allows remote attackers to execute arbitrary commands.

Detection Guidance

Detecting this vulnerability requires checking the firmware version of Advantech WISE-6610 devices. Use network scanning tools like nmap to identify affected devices and verify if they are running version 1.2.1_20251110 or earlier.

Impact Analysis

The vulnerability allows remote attackers to execute arbitrary commands on affected devices, potentially leading to unauthorized access, data theft, device compromise, or disruption of services. The high CVSS scores (9.0-9.9) indicate severe impact on confidentiality, integrity, and availability.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face compliance violations, regulatory fines, and reputational damage if exploited.

Mitigation Strategies

Immediately upgrade the firmware of all affected Advantech WISE-6610 devices to version 1.2.4_20260821 or later. Follow the vendor's official upgrade procedure to ensure proper installation and configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79697. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart