Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.
2023-08-08T11:15:12.143
2025-02-13T17:17:16.117
Modified
CVSSv3.1: 9.0 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | advantech | eki-1524_firmware | ≤ 1.24 | Yes |
| Hardware | advantech | eki-1524 | - | No |
| Operating System | advantech | eki-1522_firmware | ≤ 1.24 | Yes |
| Hardware | advantech | eki-1522 | - | No |
| Operating System | advantech | eki-1521_firmware | ≤ 1.24 | Yes |
| Hardware | advantech | eki-1521 | - | No |