---
id: CVE-2026-2670
title: >-
  A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB,
  WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB,
  WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA,
  WISE-6610P-DNA and WIS…
summary: >-
  A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB,
  WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB,
  WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA,
  WISE-6610P-DNA and WIS…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
  - CWE-78
published: '2026-02-18'
updated: '2026-09-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2670'
references:
  - url: 'https://github.com/master-abc/cve/issues/37'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-2670'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/753293'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/346467'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/346467/cti'
    label: cna@vuldb.com
  - url: 'https://www.advantech.com/'
    label: cna@vuldb.com
  - url: 'https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI'
    label: cna@vuldb.com
  - url: 'https://www.advantech.com/zh-tw/security-advisory'
    label: cna@vuldb.com
tags:
  - nvd
  - exploit-available
epss: 0.03602
epssPercentile: 0.89003
ingestedAt: '2026-09-07T07:06:47.478Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/ali-py3/exploit-CVE-2026-2670'
  checkedAt: '2026-09-25T08:20:53.720Z'
exploitAvailable: true
---

## Overview

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
