CVE-2025-62630: Advantech DeviceOn/iEdge Path Traversal
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62630?
CVE-2025-62630 is classified as a critical vulnerability due to its potential for remote code execution with system-level permissions.
How do I fix CVE-2025-62630?
To fix CVE-2025-62630, upgrade Advantech DeviceOn/iEdge to version 2.0.3 or later, where the vulnerability has been addressed.
What types of attacks does CVE-2025-62630 enable?
CVE-2025-62630 enables directory traversal attacks that can lead to remote code execution by uploading crafted configuration files.
Which software is affected by CVE-2025-62630?
CVE-2025-62630 affects Advantech DeviceOn/iEdge version 2.0.2 and prior.
What are the potential impacts of CVE-2025-62630?
The potential impacts of CVE-2025-62630 include unauthorized access to sensitive information and complete system compromise.