Advantech is a leading provider of industrial automation, embedded systems, and remote-management platforms whose vulnerability footprint spans a moderate but widely deployed product portfolio including WebAccess, R-Seenet, and iView software. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while a moderate tendency exists toward public exploit availability. The recurring exposure centers on application-layer input handling and memory-safety issues: SQL injection, cross-site scripting, path traversal, buffer-overflow conditions, and out-of-bounds writes that are characteristic of software operating at the industrial-control and remote-access boundary. Advantech's products often sit in operational-technology environments where patching cycles are lengthy and asset lifespans extend for years, making these vulnerabilities particularly consequential for defenders managing legacy industrial infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advantech over time
Signals from CVEs in this vendor scope (378 CVEs).
378 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-0854CRITICAL Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows r | Jan 15, 2016 | 9.8 | 85 | NO | YES |
CVE-2021-21805CRITICAL An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrar | Aug 5, 2021 | 9.8 | 79 | NO | YES |
CVE-2014-2364HIGH Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, | Jul 19, 2014 | 7.5 | 77 | NO | YES |
CVE-2022-2143CRITICAL The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. | Jul 22, 2022 | 9.8 | 75 | NO | YES |
CVE-2017-16720CRITICAL A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device. | Jan 5, 2018 | 9.8 | 70 | NO | YES |
CVE-2025-52694CRITICAL Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exp | Jan 12, 2026 | 9.8 | 67 | NO | YES |
CVE-2021-21801MEDIUM This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a v | Jul 16, 2021 | 6.1 | 67 | NO | YES |
CVE-2011-0340HIGH Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 6 | May 4, 2011 | 9.3 | 64 | NO | YES |
CVE-2021-22652CRITICAL Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obta | Feb 11, 2021 | 9.8 | 60 | NO | YES |
CVE-2018-6911CRITICAL The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter). | Feb 13, 2018 | 9.8 | 49 | NO | YES |
Signals from CVEs in this vendor scope (378 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advantech.
Media articles that mention a CVE ID that affects a product developed by Advantech — matched by CVE ID, not by vendor name.