CVE-2026-79698: Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.120251110. This vulnerability affects the function noderedlibapply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.420260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WISE-6610-NB/WISE-6610-EB/WISE-6610-TB/WISE-6610-JB/WISE-6610-CB/WISE-6610-EL-NB/WISE-6610-EL-EB/WISE-6610-EL-TB/WISE-6610-EL-JB/WISE-6610-EL-CB/WISE-6610P-DEA/WISE-6610P-DNA/WISE-6610P-DTAto a version that resolves this vulnerability.Fixed in 1.2.4_20260821
Event History
Frequently Asked Questions
Which systems should be prioritized for remediation?
Prioritize Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, the listed WISE-6610-EL variants, and WISE-6610P-DEA, WISE-6610P-DNA, and WISE-6610P-DTA running version 1.2.1_20251110. The issue is remotely exploitable and public exploit code is available.
What access does an attacker need to exploit this issue?
The attack can be launched remotely with low attack complexity and requires low privileges. No user interaction is required.
What is the recommended remediation?
Upgrade the affected component to version 1.2.4_20260821, which resolves the issue. The vulnerability is in the Node-RED Library function nodered_lib_apply.