Sceawere

Vulnerability Detail

CVE-2026-79698UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Command Injection in Advantech WISE-6610

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
3h ago
Vendor
Advantech
Product
WISE-6610-NB
Attack Type
Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-07T07:16:47.420Z",
  "pubdate": "2026-09-07T07:16:47.420Z",
  "executiveSummary": "A critical command injection vulnerability exists within the Node-RED Library component of several Advantech WISE-6610 series gateways, specifically version 1.2.1_20251110.\nThe vulnerability resides in the 'nodered_lib_apply' function, where insufficient validation of the 'act' argument allows an attacker to inject and execute arbitrary system commands.\nThis flaw is exploitable remotely, posing a significant security risk to the integrity and availability of the affected Industrial IoT (IIoT) devices.\nSuccessful exploitation grants an unauthenticated or remote attacker the ability to execute OS-level commands with the privileges of the underlying Node-RED process.\nGiven that the exploit is publicly available, organizations are at an elevated risk of compromise and should prioritize remediation.\nThe vendor has addressed this security weakness in version 1.2.4_20260821, and immediate firmware updates are strongly advised to mitigate the potential for unauthorized system access or arbitrary code execution.",
  "technicalDetails": "The vulnerability is classified as a command injection flaw located within the 'nodered_lib_apply' function of the Node-RED Library component in the Advantech WISE-6610 series firmware version 1.2.1_20251110.\nThe root cause stems from improper neutralization of special elements used in an OS command. Specifically, the 'act' argument, which is processed by the 'nodered_lib_apply' function, is directly passed to a system-level execution routine without adequate sanitization or input validation.\nAn attacker can exploit this by crafting a malicious payload within the 'act' parameter. By embedding shell metacharacters such as semicolons, pipes, or backticks, the attacker can break out of the intended command context to execute arbitrary instructions on the underlying Linux-based operating system.\nThe attack flow proceeds as follows: First, the attacker identifies a remote entry point that interacts with the Node-RED configuration or library management functionality. Second, the attacker sends a request containing the manipulated 'act' argument to the 'nodered_lib_apply' function. Third, the application concatenates this input into a shell command string. Fourth, the system shell interprets the injected characters, leading to the execution of the attacker's commands.\nBecause the 'nodered_lib_apply' function typically runs with the permissions assigned to the Node-RED service, the injected commands inherit these privileges, which are often sufficient to facilitate lateral movement, exfiltrate sensitive configuration files, modify device settings, or deploy persistent malware.\nThis vulnerability is particularly dangerous as it is remotely exploitable without necessitating complex pre-conditions. The availability of a public exploit simplifies the barrier to entry, enabling opportunistic attacks against exposed WISE-6610 devices. Affected models include the WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA, and WISE-6610P-DTA. The lack of robust input filtering mechanisms within the library management logic constitutes a critical failure in the secure development lifecycle of this component."
}
CVE-2026-79698: Command Injection in Advantech WISE-6610 (CRITICAL Severity, CVSS: 9.9) - Sceawere