📦 Webaccess\/vpn

by Advantech

🔍 What is Webaccess\/vpn?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34239

HIGH CVSS 7.2 Nov 6, 2025

This vulnerability allows authenticated system administrators in Advantech WebAccess/VPN to execute arbitrary commands on the server by uploading specially crafted filenames. The attacker gains execut...

CVE-2025-34247

MEDIUM CVSS 6.5 Nov 6, 2025

Advantech WebAccess/VPN versions before 1.1.5 contain a SQL injection vulnerability in the NetworksController.addNetworkAction() function. Authenticated low-privileged users can exploit this via datat...

CVE-2025-34241

MEDIUM CVSS 6.5 Nov 6, 2025

Advantech WebAccess/VPN versions before 1.1.5 contain a SQL injection vulnerability in the AjaxDeviceController.ajaxDeviceAction() function. Authenticated low-privileged users can exploit this via dat...

CVE-2025-34242

MEDIUM CVSS 6.5 Nov 6, 2025

Advantech WebAccess/VPN versions before 1.1.5 contain a SQL injection vulnerability in the AjaxNetworkController.ajaxAction() function. Authenticated low-privileged users can exploit this via datatabl...

CVE-2025-34243

MEDIUM CVSS 6.5 Nov 6, 2025

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in the AjaxFwRulesController.ajaxNetworkFwRulesAction() function. Authenticated low-privileged users can exploit t...

CVE-2025-34244

MEDIUM CVSS 6.5 Nov 6, 2025

This SQL injection vulnerability in Advantech WebAccess/VPN allows authenticated low-privileged users to inject malicious SQL queries through datatable search parameters. Successful exploitation can l...

CVE-2025-34245

MEDIUM CVSS 6.5 Nov 6, 2025

This SQL injection vulnerability in Advantech WebAccess/VPN allows authenticated low-privileged users to inject malicious SQL queries through datatable search parameters in the AjaxStandaloneVpnClient...

CVE-2025-34246

MEDIUM CVSS 6.5 Nov 6, 2025

Advantech WebAccess/VPN versions before 1.1.5 contain a SQL injection vulnerability in the AjaxPrevalidationController.ajaxAction() function. Authenticated low-privileged users can exploit this via da...

CVE-2025-34236

MEDIUM CVSS 5.4 Nov 6, 2025

Advantech WebAccess/VPN versions before 1.1.5 contain a stored cross-site scripting vulnerability in the NetworksController.addNetworkAction() function. This allows attackers to inject malicious scrip...

CVE-2025-34237

MEDIUM CVSS 5.4 Nov 6, 2025

Advantech WebAccess/VPN versions before 1.1.5 contain a stored cross-site scripting vulnerability in the StandaloneVpnClientsController.addStandaloneVpnClientAction() function. This allows attackers t...

CVE-2025-34238

MEDIUM CVSS 6.5 Nov 6, 2025

This vulnerability allows authenticated network administrators in Advantech WebAccess/VPN to read arbitrary files accessible to the web user (www-data) via path traversal. It affects versions prior to...

CVE-2025-34240

MEDIUM CVSS 6.5 Nov 6, 2025

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in the AppManagementController.appUpgradeAction() function. Authenticated low-privileged users can exploit this vi...