CRITICAL🇵🇱 Wersja polska

CVE-2025-48469

CVSS 9.6v3.1pub. 2025-06-24upd. 2025-07-09

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.

🤖 AI Analysis
How it works

The firmware update mechanism on WISE-40x0 series devices is publicly available without any authentication (CWE-306 — missing authentication for critical function). An attacker on the local network segment (AV:A vector) can directly upload a modified firmware image to the update page. The uploaded firmware may contain a backdoor or malicious code providing the attacker with elevated privileges on the device.

Impact

An attacker can install a backdoor, achieve privilege escalation, or gain full control over the device, leading to violations of confidentiality, integrity, and system availability.

Mitigation & patch

Apply patches available from the manufacturer according to references. Additionally, it is recommended to isolate WISE-40x0 devices in a dedicated network segment with restricted access and block access to the administrative interface from untrusted network segments.

Who is affected

Advantech WISE-4010LAN, WISE-4050LAN, WISE-4060LAN (including firmware for these devices) — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Advantech Wise 4010lan

    HW
    Advantech
    all versions
  • Advantech Wise 4010lan Firmware

    OS
    Advantech
    all versions
  • Advantech Wise 4050lan

    HW
    Advantech
    all versions
  • Advantech Wise 4050lan Firmware

    OS
    Advantech
    all versions
  • Advantech Wise 4060lan

    HW
    Advantech
    all versions
  • Advantech Wise 4060lan Firmware

    OS
    Advantech
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassLPE
CWE
References

Related vulnerabilities

CVE-2025-48466HIGH8.1same product

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TC...

CVE-2025-48462MEDIUM4.2same product

Successful exploitation of the vulnerability could allow an attacker to consume all available session slots an...

CVE-2025-48461MEDIUM5.0same product

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force gu...

CVE-2025-48467MEDIUM6.5same product

Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially le...

CVE-2025-48468MEDIUM6.4same product

Successful exploitation of the vulnerability could allow an attacker that has physical access to interface wit...