CVE-2025-14849: Advantech Webaccess/scada

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Affected products

  • Advantech Webaccess/scada: version 9.2.1 only

Published 2025-12-18. Last modified 2026-09-30.