---
id: CVE-2026-79697
title: >-
  A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB,
  WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB,
  WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA,
  WISE-6610P-DNA and WIS…
summary: >-
  A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB,
  WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB,
  WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA,
  WISE-6610P-DNA and WIS…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-74
  - CWE-77
vendor: Advantech
product: WISE-6610-NB
affected:
  - WISE-6610-NB 1.2.1_20251110
  - WISE-6610-EB 1.2.1_20251110
  - WISE-6610-TB 1.2.1_20251110
  - WISE-6610-JB 1.2.1_20251110
  - WISE-6610-CB 1.2.1_20251110
  - WISE-6610-EL-NB 1.2.1_20251110
  - WISE-6610-EL-EB 1.2.1_20251110
  - WISE-6610-EL-TB 1.2.1_20251110
  - WISE-6610-EL-JB 1.2.1_20251110
  - WISE-6610-EL-CB 1.2.1_20251110
  - WISE-6610P-DEA 1.2.1_20251110
  - WISE-6610P-DNA 1.2.1_20251110
  - WISE-6610P-DTA 1.2.1_20251110
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:17:29.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79697'
references:
  - url: >-
      https://uvxbywu62qm.feishu.cn/wiki/EzwXwS0vKiroHmk9rqzcjP0EnMe?from=from_copylink
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-79697'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/879208'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399512'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399512/cti'
    label: cna@vuldb.com
  - url: 'https://www.advantech.com/'
    label: cna@vuldb.com
  - url: 'https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI'
    label: cna@vuldb.com
  - url: 'https://www.advantech.com/zh-tw/security-advisory'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T13:42:20.317863Z'
epss: 0.03353
epssPercentile: 0.8817
ingestedAt: '2026-09-08T15:33:26.975Z'
---

## Overview

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
