Command Injection in Advantech WISE-6610 LoRaWAN Gateway
Command injection in the Basic Station Certificate-Deletion Handler of Advantech WISE-6610 gateways allows remote code execution. CVSS 9.9 critical. Firmware 1.2.4_20260821 patches the issue.
- Vendor
- Advantech
- Product
- WISE-6610 series (firmware 1.2.1_20251110 and earlier)
- CVSS
- 9.9
- EPSS (exploit probability)
- 3.4%
- Status
- patched
- Published
A command injection vulnerability in the basicstation_apply function of Advantech WISE-6610 firmware allows a remote attacker to inject arbitrary operating-system commands via the act parameter in the Basic Station Certificate-Deletion Handler. NVD rates the flaw CVSS 9.9 critical. A working exploit has been publicly disclosed.
Affected hardware includes all WISE-6610 variants (NB, EB, TB, JB, CB), the WISE-6610-EL line (NB, EB, TB, JB, CB), and the WISE-6610P series (DEA, DNA, DTA) running firmware 1.2.1_20251110.
Advantech released patched firmware 1.2.4_20260821 on August 21, 2026. Administrators should update all affected units through the Advantech support portal. No CISA KEV listing has been issued as of September 8, 2026.
