Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
References
Configurations
History
No history.
Information
Published : 2025-11-06 20:15
Updated : 2025-11-28 16:58
NVD link : CVE-2025-34243
Mitre link : CVE-2025-34243
CVE.ORG link : CVE-2025-34243
JSON object : View
Products Affected
advantech
- webaccess\/vpn
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
