CVE-2025-58423

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
06/11/2025
Last modified:
21/11/2025

Description

Due to insufficient sanitization, an attacker can upload a specially <br /> crafted configuration file to cause a denial-of-service condition, <br /> traverse directories, or read/write files, within the context of the <br /> local system account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advantech:deviceon\/iedge:*:*:*:*:*:*:*:* 2.0.2 (including)