Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilitycritical-infrastructure-threatwidely-deployed-product-advisoryoperational-disruption

Multiple Critical Vulnerabilities in Advantech WebAccess/SCADA

Updated 3mo agoFirst seen Dec 18, 20253 sources

Advantech WebAccess/SCADA has been found to contain several critical vulnerabilities, including an unrestricted file upload flaw (CVE-2025-14849) and a directory traversal vulnerability (CVE-2025-14850). The unrestricted file upload issue could allow a remote attacker to execute arbitrary code on affected systems, while the directory traversal flaw may enable attackers to delete arbitrary files. Both vulnerabilities are remotely exploitable and have been assigned high CVSS scores, indicating significant risk to organizations using this software in critical infrastructure sectors.

CISA has issued an advisory confirming that these vulnerabilities affect Advantech WebAccess/SCADA version 9.2.1, and recommends updating to version 9.2.2 to mitigate the risks. The vulnerabilities impact organizations in sectors such as critical manufacturing, energy, and water and wastewater, with deployments worldwide. Exploitation of these flaws could allow authenticated attackers to read or modify remote databases, potentially leading to severe operational disruptions.

Share:
Multiple Critical Vulnerabilities in Advantech WebAccess/SCADA
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 18, 20256mo ago

CVE records published for Advantech file upload and path traversal flaws

Public CVE entries were published for CVE-2025-14849, an unrestricted file upload flaw, and CVE-2025-14850, a directory traversal flaw in Advantech WebAccess/SCADA. The records described remote exploitation risk and linked the issues to CISA/ICS-CERT tracking.

CISA publishes advisory on Advantech WebAccess/SCADA vulnerabilities

CISA published advisory ICSA-25-352-06 warning that multiple critical vulnerabilities affect Advantech WebAccess/SCADA 9.2.1 used across sectors including manufacturing, energy, and water. CISA said no public exploitation had been reported at the time of the initial advisory and urged immediate mitigations.

Advantech releases WebAccess/SCADA 9.2.2 to fix multiple flaws

Advantech released version 9.2.2 of WebAccess/SCADA to address multiple critical vulnerabilities affecting version 9.2.1. The fixes cover issues that could let authenticated attackers manipulate files, execute code, or access remote databases.

Researcher reports Advantech WebAccess/SCADA vulnerabilities to CISA

Alex Williams of Pellera Technologies reported multiple vulnerabilities in Advantech WebAccess/SCADA to CISA, including directory traversal, unrestricted file upload, absolute path traversal, and SQL injection issues. The exact reporting date is not stated in the references.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.