May 8, 2023, 1:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.

advantech command command injection cve device devices injection input name request vulnerability

Malware Analyst - TASO / Active Secret

@ Peraton | Arlington, VA, United States

Information Security Engineer

@ Deel | Anywhere (APAC)

Cybersecurity Engineer

@ Booz Allen Hamilton | USA, DC, Washington (1125 15th St NW)

Director, Security Engineering

@ Warner Bros. Discovery | GA Atlanta 1050 Techwood Drive NW

Consultant Senior Securité Réseaux

@ Devoteam | Tunis, Tunisia

SOC Analyst, Mid

@ Peraton | Washington, DC, United States