8.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.
AI Analysis
Command injection vulnerability in AppManagementController.appUpgradeAction() allowing authenticated administrators to execute arbitrary commands
Basic Information
ID
CVE-2025-34239
Source
VulnCheck
Published
Nov 6, 2025 at 19:44
Affected Product
Vendor
Advantech
Product
WebAccess/VPN
Affected Versions
Advantech WebAccess/VPN 0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Advantech
Product
WebAccess/VPN
Version
< 1.1.5