Advantech WebAccess/VPN SQL Injection Vulnerability in AjaxNetworkController

Vulnerability

A SQL injection vulnerability has been identified in Advantech WebAccess/VPN versions prior to 1.1.5. The issue resides in the AjaxNetworkController.ajaxAction() method, where an authenticated low-privileged observer user can inject SQL through datatable search parameters. This injection could lead to unauthorized disclosure of database information.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate database queries. This could result in unauthorized data access, data modification, or in some cases, executing administrative operations on the database.

Remediation

Users are advised to upgrade to Advantech WebAccess/VPN version 1.1.5.

Added: Nov 6, 2025, 10:04 PM
Updated: Nov 6, 2025, 10:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.