CVE-2024-39275: Advantech Adam-5630 Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.

Affected products

  • Advantech Adam-5630 Firmware: before 2.5.2 (fixed in 2.5.2)

Published 2024-09-27. Last modified 2026-06-17.