Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.
The firmware update mechanism on WISE-40x0 series devices is publicly available without any authentication (CWE-306 — missing authentication for critical function). An attacker on the local network segment (AV:A vector) can directly upload a modified firmware image to the update page. The uploaded firmware may contain a backdoor or malicious code providing the attacker with elevated privileges on the device.
An attacker can install a backdoor, achieve privilege escalation, or gain full control over the device, leading to violations of confidentiality, integrity, and system availability.
Apply patches available from the manufacturer according to references. Additionally, it is recommended to isolate WISE-40x0 devices in a dedicated network segment with restricted access and block access to the administrative interface from untrusted network segments.
Advantech WISE-4010LAN, WISE-4050LAN, WISE-4060LAN (including firmware for these devices) — specific versions indicated in manufacturer references
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAdvantech Wise 4010lan
HWAdvantechall versionsAdvantech Wise 4010lan Firmware
OSAdvantechall versionsAdvantech Wise 4050lan
HWAdvantechall versionsAdvantech Wise 4050lan Firmware
OSAdvantechall versionsAdvantech Wise 4060lan
HWAdvantechall versionsAdvantech Wise 4060lan Firmware
OSAdvantechall versions
Related vulnerabilities
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TC...
Successful exploitation of the vulnerability could allow an attacker to consume all available session slots an...
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force gu...
Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially le...
Successful exploitation of the vulnerability could allow an attacker that has physical access to interface wit...