Advantech WISE-6610-NB Background Management openvpn_apply os command injection
Summary
| CVE | CVE-2026-2670 |
|---|---|
| State | PUBLISHED |
| Assigner | VulDB |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-02-18 22:16:27 UTC |
| Updated | 2026-09-07 06:17:18 UTC |
| Description | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data." |
Risk And Classification
Primary CVSS: v4.0 7.3 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-77 | CWE-78 | CWE-78 OS Command Injection | CWE-77 Command Injection
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.3 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/C... |
| 4.0 | CNA | DECLARED | 8.6 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
| 3.1 | [email protected] | Secondary | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| 3.0 | CNA | DECLARED | 7.2 | HIGH | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| 2.0 | [email protected] | Secondary | 8.3 | AV:N/AC:L/Au:M/C:C/I:C/A:C | |
| 2.0 | CNA | DECLARED | 8.3 | AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:OF/RC:C |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Advantech | WISE-6610-NB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-NB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-EB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-EB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-TB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-TB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-JB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-JB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-CB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-CB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-EL-NB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-EL-NB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-EL-EB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-EL-EB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-EL-TB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-EL-TB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-EL-JB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-EL-JB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610-EL-CB | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610-EL-CB | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610P-DEA | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610P-DEA | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610P-DNA | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610P-DNA | unaffected 1.2.4_20260821 | Not specified |
| CNA | Advantech | WISE-6610P-DTA | affected 1.2.1_20251110 | Not specified |
| CNA | Advantech | WISE-6610P-DTA | unaffected 1.2.4_20260821 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.advantech.com | [email protected] | www.advantech.com | |
| www.advantech.com/en-us/support/details/firmware | [email protected] | www.advantech.com | |
| www.advantech.com/zh-tw/security-advisory | [email protected] | www.advantech.com | |
| github.com/master-abc/cve/issues/37 | [email protected] | github.com | |
| vuldb.com/submit/753293 | [email protected] | vuldb.com | |
| vuldb.com/vuln/346467 | [email protected] | vuldb.com | |
| vuldb.com/cve/CVE-2026-2670 | [email protected] | vuldb.com | |
| vuldb.com/vuln/346467/cti | [email protected] | vuldb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: jiefengliang (VulDB User) (en)
CNA: VulDB CNA Team (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-02-18T00:00:00.000Z | Advisory disclosed |
| CNA | 2026-02-18T01:00:00.000Z | VulDB entry created |
| CNA | 2026-09-02T00:00:00.000Z | Countermeasure disclosed |
| CNA | 2026-09-07T08:02:45.000Z | VulDB entry last update |
There are currently no legacy QID mappings associated with this CVE.