CVE-2025-34239: Advantech Webaccess/vpn
High severity, CVSS 7.2. EPSS: 1.7% chance of exploitation in the next 30 days.
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.
Affected products
- Advantech Webaccess/vpn: before 1.1.5 (fixed in 1.1.5)
Published 2025-11-06. Last modified 2026-10-07.