is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
Project Subscriptions
No advisories yet.
Solution
Advantech recommends users apply the following mitigations and update to WebAccess/SCADA: Version 9.2.2 https://www.advantech.com/en-us/support/details/installation .
Workaround
No workaround given by the vendor.
Wed, 31 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech webaccess\/scada
|
|
| CPEs | cpe:2.3:a:advantech:webaccess\/scada:9.2.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Advantech webaccess\/scada
|
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech
Advantech webaccess/scada |
|
| Vendors & Products |
Advantech
Advantech webaccess/scada |
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. | |
| Title | Advantech WebAccess/SCADA Unrestricted Upload of File with Dangerous Type | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-12-18T21:46:46.491Z
Reserved: 2025-12-17T18:58:28.259Z
Link: CVE-2025-14849
Updated: 2025-12-18T21:02:52.221Z
Status : Analyzed
Published: 2025-12-18T21:15:52.743
Modified: 2025-12-31T19:47:42.147
Link: CVE-2025-14849
No data.
OpenCVE Enrichment
Updated: 2025-12-19T09:15:49Z