Advantech WebAccess/VPN SQL Injection Vulnerability in AjaxFwRulesController

Vulnerability

A SQL injection vulnerability has been identified in Advantech WebAccess/VPN versions prior to 1.1.5. The issue resides in the AjaxFwRulesController.ajaxNetworkFwRulesAction() method, where an authenticated low-privileged observer user can inject SQL through datatable search parameters. This injection could lead to unauthorized disclosure of database information.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker could manipulate database queries to access, modify, or delete database information. In this specific case, the vulnerability could be exploited to disclose sensitive database information.

Remediation

Users are advised to upgrade to Advantech WebAccess/VPN version 1.1.5.

Added: Nov 6, 2025, 10:04 PM
Updated: Nov 6, 2025, 10:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.