CVE-2025-58423: Advantech DeviceOn/iEdge Path Traversal
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58423?
CVE-2025-58423 is considered a high-severity vulnerability due to the potential for denial-of-service and unauthorized file access.
How can I fix CVE-2025-58423?
To fix CVE-2025-58423, update Advantech DeviceOn/iEdge to version 2.0.3 or later, where the vulnerability has been addressed.
What systems are affected by CVE-2025-58423?
CVE-2025-58423 affects Advantech DeviceOn/iEdge versions 2.0.2 and prior.
What types of attacks are possible with CVE-2025-58423?
An attacker can exploit CVE-2025-58423 to cause denial-of-service, traverse directories, or read/write files on the local system.
Is there a workaround for CVE-2025-58423?
There are no official workarounds provided for CVE-2025-58423; the only solution is to apply the available software update.