CVE-2025-59171: Advantech DeviceOn/iEdge Path Traversal
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59171?
CVE-2025-59171 is rated as a critical vulnerability due to the potential for remote code execution with system-level permissions.
How do I fix CVE-2025-59171?
To mitigate CVE-2025-59171, users should update Advantech DeviceOn/iEdge to version 2.0.3 or later where the vulnerability is addressed.
What type of attack is possible with CVE-2025-59171?
CVE-2025-59171 allows attackers to upload a specially crafted configuration file, leading to directory traversal and remote code execution.
Which software versions are affected by CVE-2025-59171?
CVE-2025-59171 affects Advantech DeviceOn/iEdge version 2.0.2 and prior.
Who is vulnerable to CVE-2025-59171?
Organizations using Advantech DeviceOn/iEdge version 2.0.2 or earlier are vulnerable to CVE-2025-59171.