A publicly disclosed command injection flaw in the Basic Station certificate-deletion handler of Advantech's WISE-6610 gateway family lets a remote, low-privileged attacker execute arbitrary commands, with a patched firmware release already available.
What Is It
The vulnerability sits in the basicstation_apply function of the Basic Station Certificate-Deletion Handler on Advantech WISE-6610 series devices running firmware 1.2.1_20251110. Manipulation of the act argument results in command injection. The attack can be initiated remotely and requires only low privileges with no user interaction.
VulDB, the assigning CNA, publishes a CVSS 4.0 base score of 8.6 (HIGH) alongside the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. Those two do not agree: that vector, network attack vector, low complexity, low privileges, and HIGH impact on both the vulnerable system and subsequent systems, computes to roughly 9.3, not 8.6. The published 8.6 is consistent with the same vector carrying no subsequent-system impact (SC:N/SI:N/SA:N), which is VulDB's more usual scoring pattern, so one of the two published values is in error and the subsequent-system metrics are the likely culprit. Treat the exact CVSS 4.0 number and the subsequent-system metrics as unconfirmed pending a corrected upstream entry.
The CVSS 3.1 score of 9.9 (CRITICAL) under CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H is internally consistent, the vector does compute to 9.9, and is the more reliable of the two ratings as published.
Why It Matters
The exploit has been publicly disclosed and may be utilized. The CVE does not appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-07 (https://www.cisa.gov/known-exploited-vulnerabilities-catalog), so active exploitation is not confirmed by KEV at this time, but public disclosure meaningfully lowers the bar for opportunistic use.
Both scoring vectors rate confidentiality, integrity, and availability impact on the vulnerable component as HIGH. The CVSS 3.1 vector additionally sets scope to changed (S:C), meaning a successful injection is expected to reach beyond the vulnerable component itself; the CVSS 4.0 subsequent-system metrics point the same direction but are part of the disputed scoring noted above, so the scope-change conclusion rests on the 3.1 vector. Network attack vector plus low attack complexity makes reachable devices a practical target regardless of which base score is correct; both ratings land in HIGH or above.
What's Vulnerable
Advantech firmware version 1.2.1_20251110 on the following products:
- WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB
- WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB
- WISE-6610P-DEA, WISE-6610P-DNA, WISE-6610P-DTA
The affected component in every case is the Basic Station Certificate-Deletion Handler.
Patch Status
Fixed. Advantech released version 1.2.4_20260821, which NVD lists as unaffected across all thirteen products. Upgrading to 1.2.4_20260821 mitigates the issue, and upgrading the affected component is advised. Per the advisory, the vendor was contacted early, responded professionally, and quickly released a fixed version. Operators of any listed model should apply the firmware update from Advantech's support portal.
Sources
- NVD, CVE-2026-79697: https://nvd.nist.gov/vuln/detail/CVE-2026-79697
- VulDB, CVE-2026-79697: https://vuldb.com/cve/CVE-2026-79697
- VulDB, Entry 399512: https://vuldb.com/vuln/399512
- VulDB, Threat intelligence: https://vuldb.com/vuln/399512/cti
- VulDB, Submission 879208: https://vuldb.com/submit/879208
- CISA Known Exploited Vulnerabilities catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Researcher writeup: https://uvxbywu62qm.feishu.cn/wiki/EzwXwS0vKiroHmk9rqzcjP0EnMe?from=from_copylink
- Advantech firmware download: https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI
- Advantech security advisories: https://www.advantech.com/zh-tw/security-advisory