Advantech security advisory (AV26-907)

Published September 10, 2026

A flaw in Advantech's WISE-6610 industrial gateways lets attackers crash the device or run their own code by sending specially crafted network messages. These gateways connect factory equipment to networks, so a crash or takeover could disrupt production lines or let attackers spy on or control industrial systems.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Exploited
Not confirmedNo confirmation recorded

How it works

  • The WISE-6610 gateway fails to properly check network messages sent to its control protocols.
  • An attacker sends a malformed message to the gateway's communication port, which the device does not reject.
  • This causes the gateway to either crash or let the attacker run commands on the device itself.
  • The attacker does not need special access or credentials to send these messages.

What to do

Check if you use Advantech WISE-6610 gateways in your facility. The advisory does not name an exact version cutoff, so exposure cannot be decided by version alone. Consult the full advisory for the affected release range and prerequisites. If you run these gateways, you are affected and must apply updates when Advantech releases them.

Monitor the official Advantech support site or the CCCS advisory for updates. Apply any patches or workarounds Advantech provides as soon as they are available. Check your gateway's firmware version and compare it to the advisory's affected range to confirm exposure.

Technical details

A critical authentication bypass vulnerability (CVE-NEWS-4865794e478b9e2e3e) affects multiple versions and models of the Advantech WISE-6610 industrial gateway. Attackers with network access can bypass authentication and gain unauthorized administrative control over affected devices, potentially enabling remote code execution or lateral movement within industrial networks. The issue was disclosed on September 10, 2026, with no fixed versions or patches publicly confirmed at this time.