CVE-2025-34244
EUVD-2025-3817106.11.2025, 20:15
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| advantech | webaccess\/vpn | 𝑥 < 1.1.5 |
𝑥
= Vulnerable software versions