5.1

CVSS4.0

CVE-2025-34247 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via NetworksController.addNetworkAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:49 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

5.3

CVSS4.0

CVE-2025-34246 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxPrevalidationController.ajaxAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:49 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

5.3

CVSS4.0

CVE-2025-34245 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxStandaloneVpnClientsController.ajaxAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:48 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

5.3

CVSS4.0

CVE-2025-34244 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxDeviceFwRulesAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:47 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

5.3

CVSS4.0

CVE-2025-34243 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxNetworkFwRulesAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:47 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

8.6

CVSS4.0

CVE-2025-34242 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxNetworkController.ajaxAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:46 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

5.3

CVSS4.0

CVE-2025-34241 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxDeviceController.ajaxDeviceAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:45 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

8.6

CVSS4.0

CVE-2025-34240 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AppManagementController.appUpgradeAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:45 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

8.6

CVSS4.0

CVE-2025-34239 - Advantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.

📅 Published: Nov. 6, 2025, 7:44 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

6.9

CVSS4.0

CVE-2025-34238 - Advantech WebAccess/VPN < 1.1.5 Path Traversal via AjaxStandaloneVpnClientsController.ajaxDownloadR…

Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web …

📅 Published: Nov. 6, 2025, 7:43 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.
Total resulsts: 317430
Page 21 of 31,743
« previous page » next page
Filters