CVE-2025-34239 - Advantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()
CVE ID : CVE-2025-34239
Published : Nov. 6, 2025, 8:15 p.m. | 1 hour, 21 minutes ago
Description : Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Nov. 6, 2025, 8:15 p.m. | 1 hour, 21 minutes ago
Description : Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...