Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE
A command injection in the WISE-6610 LoRaWAN gateway's Basic Station handler allows remote code execution. Exploit is public. Patch: firmware 1.2.4_20260821.

The basicstation_apply function in Advantech WISE-6610 firmware handles certificate-deletion requests for the device’s built-in LoRa Basics Station packet forwarder. The function accepts an act parameter from a network request and passes it to an underlying command without sanitizing the input. That omission is CVE-2026-79697, rated CVSS 9.9 critical by NVD. The attack is remotely initiated, and a working exploit has been publicly disclosed.
Affected hardware spans the full WISE-6610 family running firmware 1.2.1_20251110: standard variants (NB, EB, TB, JB, CB), the extended WISE-6610-EL line (NB, EB, TB, JB, CB), and the WISE-6610P models (DEA, DNA, DTA). That accounts for the bulk of the installed WISE-6610 base.
Why a gateway compromise matters
The WISE-6610 series sits at the aggregation point of a LoRaWAN sensor network. It collects low-power device traffic from endpoints across a facility or campus and bridges it to the network server for processing. Controlling the gateway means an attacker can inspect, modify, or silently drop sensor readings before they reach the operations layer, without ever touching the end devices themselves. In deployments where sensor telemetry feeds safety systems or process control decisions, that position is significant.
This is a recurring problem with embedded OT hardware. The same physical-layer devices that are hardest to update are often the ones most exposed to network-reachable vulnerabilities, as seen in recent coverage of ZBT routers shipped with factory-installed root backdoors and Forescout researchers porting an RCE across WAGO PLC variants.
Patch
Advantech responded to responsible disclosure promptly, according to NVD’s published advisory. Patched firmware 1.2.4_20260821 was released August 21, 2026. NVD published the CVE on September 7, 2026.
The remediation path is straightforward: identify every WISE-6610 unit on the OT network, verify the installed firmware version, and update to 1.2.4_20260821 via the Advantech support portal. Devices that cannot be immediately patched should have network access restricted at the infrastructure level until the update is applied.
No CISA KEV listing has been issued for CVE-2026-79697 as of September 8, 2026.
- [ CRITICAL ]CVE-2026-79697Command Injection in Advantech WISE-6610 LoRaWAN Gateway
Found this useful? Share it.


