Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Advantech

First CVE: Jan 6, 2009Active for: 18 yearsTotal CVEs: 378
53.4
VTI Score
TOP TARGET

Advantech is a leading provider of industrial automation, embedded systems, and remote-management platforms whose vulnerability footprint spans a moderate but widely deployed product portfolio including WebAccess, R-Seenet, and iView software. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while a moderate tendency exists toward public exploit availability. The recurring exposure centers on application-layer input handling and memory-safety issues: SQL injection, cross-site scripting, path traversal, buffer-overflow conditions, and out-of-bounds writes that are characteristic of software operating at the industrial-control and remote-access boundary. Advantech's products often sit in operational-technology environments where patching cycles are lengthy and asset lifespans extend for years, making these vulnerabilities particularly consequential for defenders managing legacy industrial infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
378
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Advantech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 6, 2009
17 years ago
Most Recent CVE
Jan 12, 2026
193 days ago

Products(95 total)

Top CVEs

Signals from CVEs in this vendor scope (378 CVEs).

378 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-0854CRITICAL
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows r
Jan 15, 20169.885NOYES
CVE-2021-21805CRITICAL
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrar
Aug 5, 20219.879NOYES
CVE-2014-2364HIGH
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter,
Jul 19, 20147.577NOYES
CVE-2022-2143CRITICAL
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.
Jul 22, 20229.875NOYES
CVE-2017-16720CRITICAL
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.
Jan 5, 20189.870NOYES
CVE-2025-52694CRITICAL
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exp
Jan 12, 20269.867NOYES
CVE-2021-21801MEDIUM
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a v
Jul 16, 20216.167NOYES
CVE-2011-0340HIGH
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 6
May 4, 20119.364NOYES
CVE-2021-22652CRITICAL
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obta
Feb 11, 20219.860NOYES
CVE-2018-6911CRITICAL
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).
Feb 13, 20189.849NOYES
View all 378 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products378 CVEs
32%
43%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local43 (11.4%)
Network268 (70.9%)
Unknown56 (14.8%)
Physical1 (0.3%)
Adjacent Network10 (2.6%)
Attack Complexity
Low313 (82.8%)
High9 (2.4%)
Unknown56 (14.8%)
User Interaction
None255 (67.5%)
Unknown56 (14.8%)
Required67 (17.7%)
Privileges Required
Low99 (26.2%)
High26 (6.9%)
None197 (52.1%)
Unknown56 (14.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (378 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
8 CVEs
2.1% of CVEs· 97th percentile
Nuclei
7 CVEs
1.9% of CVEs· 95th percentile
ExploitDB
18 CVEs
4.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Advantech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Advantech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Advantech's Products

View all 10 CNAs →

Top CWEs