<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WISE-6610-EL-TB (&lt;= 1.2.1_20251110) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wise-6610-el-tb--1.2.1_20251110/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 08:51:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wise-6610-el-tb--1.2.1_20251110/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Command Injection Vulnerability in Advantech WISE-6610 Gateways (CVE-2026-79697)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-79697/</link><pubDate>Mon, 07 Sep 2026 08:51:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-79697/</guid><description>Advantech WISE-6610 series gateways are vulnerable to unauthenticated remote command injection via the Basic Station Certificate-Deletion Handler, potentially leading to full system compromise.</description><content:encoded><![CDATA[<p>CVE-2026-79697 is a critical remote command injection vulnerability affecting multiple models within the Advantech WISE-6610 series of industrial IoT gateways running firmware version 1.2.1_20251110. The vulnerability resides within the 'basicstation_apply' function of the Basic Station Certificate-Deletion Handler component. By sending a maliciously crafted request that manipulates the 'act' argument, an unauthenticated remote attacker can achieve arbitrary command execution on the underlying operating system of the gateway. The exploit for this vulnerability is publicly disclosed, increasing the risk of exploitation for exposed devices. Defenders should prioritize patching, as this gateway series is often used in sensitive industrial environments where persistent access could lead to lateral movement or operational disruption.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full system compromise of the affected WISE-6610 gateway, which may grant an attacker a persistent foothold within the industrial network. Given the role of these devices as IoT gateways, an attacker could potentially intercept, modify, or disrupt communications between field sensors and backend control systems. There are no specific victim counts provided, but the severity of a 9.9 CVSS score and the public availability of the exploit necessitates immediate remediation for all internet-facing instances of this hardware.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all affected WISE-6610 series devices to firmware version 1.2.4_20260821 immediately to mitigate the underlying command injection vector.</li>
<li>Implement strict firewall controls to prevent unauthorized remote access to the web-based administrative interface of these gateways.</li>
<li>Audit network traffic for unusual outbound connections originating from WISE-6610 devices, which may indicate successful exploitation and subsequent command-and-control activity.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>iot</category><category>vulnerability</category><category>cve</category><category>network-security</category></item></channel></rss>