CVE-2018-15705: Advantech Webaccess

Medium severity, CVSS 6.5. EPSS: 12.2% chance of exploitation in the next 30 days.

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.

Affected products

  • Advantech Webaccess: version 8.3.1 only; version 8.3.2 only

Published 2018-10-31. Last modified 2026-06-17.