CVE 5.1 MEDIUM

Advantech WebAccess/VPN < 1.1.5 SQL Injection via NetworksController.addNetworkAction()_CVE-2025-34247

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

Basic Information

ID CVE-2025-34247
Source VulnCheck
Published Nov 6, 2025 at 19:49
Modified Nov 6, 2025 at 20:05

Affected Product

Vendor Advantech
Product WebAccess/VPN
Affected Versions Advantech WebAccess/VPN 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.