Advantech Products SQL Injection Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A SQL injection vulnerability has been identified in multiple Advantech products, including SaaS Composer, IoTSuite Growth and Starter Linux docker, IoT Edge Linux docker and Windows, WebAccess/SCADA, and ECOWatch. This vulnerability affects several different versions prior to the latest releases. Successful exploitation could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially leading to unauthorized access, modification, or deletion of sensitive information within the database.

Impact

Exploitation of this vulnerability could allow for arbitrary command execution, with the potential to access, modify, or delete sensitive database information.

Remediation

Users and administrators are advised to update to the latest versions. Specific update instructions are available for each affected product on the Advantech website or through their technical support channels.

Added: May 13, 2026, 5:00 PM
Updated: May 13, 2026, 5:00 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
3.1
exploitability
4.9
remediation
7.7
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.