CVE-2025-34243
06.11.2025, 20:15
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability inAjaxFwRulesController.ajaxNetworkFwRulesAction()that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
| Vendor | Product | Version |
|---|---|---|
| advantech | webaccess\/vpn | 𝑥 < 1.1.5 |
𝑥
= Vulnerable software versions