2024

2023

2022

2021

2020

CVE-2020-10603 (v3: 8.8) 9 Apr 2020
WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.

2019

CVE-2019-13552 (v3: 8.8) 18 Sep 2019
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution.

2018

CVE-2018-6911 (v3: 9.8) 13 Feb 2018
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).

2017

2016

2015