top of page
perceptive_background_267k.jpg

Advantech WebAccess/SCADA

Published:

18 december 2025 om 12:00:00

Alert date:

18 december 2025 om 18:04:12

Source:

cisa.gov

Click to open the original link from this advisory

Multiple critical vulnerabilities discovered in Advantech WebAccess/SCADA version 9.2.1 affecting critical infrastructure sectors worldwide. Five CVEs identified including path traversal, unrestricted file upload, absolute path traversal, and SQL injection vulnerabilities with CVSS scores ranging from 4.3 to 8.8. Successful exploitation could allow authenticated attackers to read or modify remote databases, execute arbitrary code, delete files, or determine file existence. Vendor has released version 9.2.2 as a fix. Product is deployed globally in critical manufacturing, energy, and water/wastewater sectors. No known public exploitation reported at time of advisory publication.

Technical details

Mitigation steps:

Affected products:

Advantech WebAccess/SCADA

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page