Advantech Products JTAG Interface Vulnerability Allowing Firmware Injection or Modification

Vulnerability

A vulnerability exists in certain Advantech products that allows an attacker with physical access to the device to use the JTAG interface for injecting or modifying firmware. This issue has been addressed in firmware version A2.02 B00, which disables the JTAG interface during normal operation.

Impact

Exploitation of this vulnerability could lead to unauthorized firmware modification or injection, potentially allowing for malicious alterations to the device's functionality or behavior.

Remediation

Users and administrators are advised to update to firmware version A2.02 B00, which disables the JTAG interface during normal operation.

Added: Jun 24, 2025, 3:20 AM
Updated: Jun 24, 2025, 3:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.