CVE-2013-1627: Advantech Studio

High severity, CVSS 7.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.

Affected products

  • Advantech Advantech Studio: version 6.1 only
  • InduSoft Web Studio: version 6.1 only; version 7.0 only; version 7.0b2 only

Published 2013-03-11. Last modified 2026-06-16.