← Back to browse · API

CVE-2026-2670

Severity
HIGH
CVSS
8.6
EPSS
0.16301
Risk score
40.11
CISA KEV
No
PoC
No
Published
2026-02-18
Modified
2026-02-23
First seen
2026-08-06
Aliases
CNVD-2026-15863, EUVD-2026-7633, GHSA-36PH-WMRQ-6HRJ
Products
Advantech WISE-6610 1.2.1_20251110, Advantech:WISE-6610 1.2.1_20251110
Sources
cnvd CNVD-2026-15863
euvd EUVD-2026-7633

Description

A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

References