{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wise-6610-jb--1.2.1_20251110/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-79697"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WISE-6610-NB (\u003c= 1.2.1_20251110)","WISE-6610-EB (\u003c= 1.2.1_20251110)","WISE-6610-TB (\u003c= 1.2.1_20251110)","WISE-6610-JB (\u003c= 1.2.1_20251110)","WISE-6610-CB (\u003c= 1.2.1_20251110)","WISE-6610-EL-NB (\u003c= 1.2.1_20251110)","WISE-6610-EL-EB (\u003c= 1.2.1_20251110)","WISE-6610-EL-TB (\u003c= 1.2.1_20251110)","WISE-6610-EL-JB (\u003c= 1.2.1_20251110)","WISE-6610-EL-CB (\u003c= 1.2.1_20251110)","WISE-6610P-DEA (\u003c= 1.2.1_20251110)","WISE-6610P-DNA (\u003c= 1.2.1_20251110)","WISE-6610P-DTA (\u003c= 1.2.1_20251110)"],"_cs_severities":["critical"],"_cs_tags":["iot","vulnerability","cve","network-security"],"_cs_type":"advisory","_cs_vendors":["Advantech"],"content_html":"\u003cp\u003eCVE-2026-79697 is a critical remote command injection vulnerability affecting multiple models within the Advantech WISE-6610 series of industrial IoT gateways running firmware version 1.2.1_20251110. The vulnerability resides within the 'basicstation_apply' function of the Basic Station Certificate-Deletion Handler component. By sending a maliciously crafted request that manipulates the 'act' argument, an unauthenticated remote attacker can achieve arbitrary command execution on the underlying operating system of the gateway. The exploit for this vulnerability is publicly disclosed, increasing the risk of exploitation for exposed devices. Defenders should prioritize patching, as this gateway series is often used in sensitive industrial environments where persistent access could lead to lateral movement or operational disruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise of the affected WISE-6610 gateway, which may grant an attacker a persistent foothold within the industrial network. Given the role of these devices as IoT gateways, an attacker could potentially intercept, modify, or disrupt communications between field sensors and backend control systems. There are no specific victim counts provided, but the severity of a 9.9 CVSS score and the public availability of the exploit necessitates immediate remediation for all internet-facing instances of this hardware.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all affected WISE-6610 series devices to firmware version 1.2.4_20260821 immediately to mitigate the underlying command injection vector.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall controls to prevent unauthorized remote access to the web-based administrative interface of these gateways.\u003c/li\u003e\n\u003cli\u003eAudit network traffic for unusual outbound connections originating from WISE-6610 devices, which may indicate successful exploitation and subsequent command-and-control activity.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T08:51:20Z","date_published":"2026-09-07T08:51:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-79697/","summary":"Advantech WISE-6610 series gateways are vulnerable to unauthenticated remote command injection via the Basic Station Certificate-Deletion Handler, potentially leading to full system compromise.","title":"Critical Command Injection Vulnerability in Advantech WISE-6610 Gateways (CVE-2026-79697)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-79697/"}],"language":"en","title":"CraftedSignal Threat Feed - WISE-6610-JB (\u003c= 1.2.1_20251110)","version":"https://jsonfeed.org/version/1.1"}