CVE-2026-79697: Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.120251110. This affects the function basicstationapply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.420260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WISE-6610 basicstation_apply (Basic Station Certificate-Deletion Handler)to a version that resolves this vulnerability.Fixed in 1.2.4_20260821
Event History
Frequently Asked Questions
Which devices and versions should be prioritized for remediation?
The issue is reported in WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA, and WISE-6610P-DTA running version 1.2.1_20251110. Upgrade affected devices to version 1.2.4_20260821.
What level of access does an attacker need to exploit this issue?
The attack can be initiated remotely and requires low privileges. It does not require user interaction or complex attack conditions.
Is exploitation likely to be practical?
Yes. Public exploit disclosure has occurred, and the disclosed exploit may be used by attackers.
What is the impact of successful exploitation?
Successful exploitation of the Basic Station Certificate-Deletion Handler's basicstation_apply function can result in command injection. The reported severity metrics indicate potential high impact to confidentiality, integrity, and availability, including impact beyond the vulnerable security authority.