CVE-2025-48469

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.
References
Link Resource
https://jro.sg/CVEs/CVE-2025-48469/ Exploit Third Party Advisory
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/ Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4060lan:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4050lan:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4010lan:-:*:*:*:*:*:*:*

History

09 Jul 2025, 15:21

Type Values Removed Values Added
CPE cpe:2.3:h:advantech:wise-4050lan:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4060lan:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4010lan:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*
First Time Advantech
Advantech wise-4060lan Firmware
Advantech wise-4050lan Firmware
Advantech wise-4060lan
Advantech wise-4050lan
Advantech wise-4010lan
Advantech wise-4010lan Firmware
References () https://jro.sg/CVEs/CVE-2025-48469/ - () https://jro.sg/CVEs/CVE-2025-48469/ - Exploit, Third Party Advisory
References () https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/ - () https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/ - Third Party Advisory

25 Jun 2025, 13:15

Type Values Removed Values Added
CWE CWE-306
Summary
  • (es) La explotación exitosa de la vulnerabilidad podría permitir que un atacante no autenticado cargue firmware a través de una página de actualización pública, lo que podría conducir a la instalación de una puerta trasera o a una escalada de privilegios.

24 Jun 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 03:15

Updated : 2025-07-09 15:21


NVD link : CVE-2025-48469

Mitre link : CVE-2025-48469

CVE.ORG link : CVE-2025-48469


JSON object : View

Products Affected

advantech

  • wise-4050lan
  • wise-4060lan
  • wise-4010lan
  • wise-4050lan_firmware
  • wise-4060lan_firmware
  • wise-4010lan_firmware
CWE
CWE-306

Missing Authentication for Critical Function