📦

deviceon\/iedge

Vendor: advantech

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 9 Total Indexed
Avg. EPSS 0.49% Exploit Prob.
Latest CVE CVE-2025-64302 Nov 06

Security Vulnerability Index

Page 1 / 1
5.3 CVSS

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.

EPSS: 0.23%
8.7 CVSS

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

EPSS: 0.66%
8.7 CVSS

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

EPSS: 0.69%
8.7 CVSS

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

EPSS: 0.51%
8.8 CVSS

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

EPSS: 0.37%