CVE-2019-3940: Advantech Webaccess

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.

Affected products

Published 2019-04-09. Last modified 2026-06-17.