CVE-2024-39364: Advantech Adam-5630
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without discrimination of origin or level of privileges of the user sending the commands.
Affected products
- Advantech Adam-5630: before v2.5.2 (fixed in v2.5.2)
Published 2024-09-27. Last modified 2026-06-17.