Directory Traversal Vulnerability in Advantech WebAccess/SCADA
CVE-2025-67653

5.3MEDIUM

Key Information:

Vendor

Advantech

Vendor
CVE Published:
18 December 2025

What is CVE-2025-67653?

Advantech WebAccess/SCADA has a directory traversal vulnerability that enables attackers to exploit this weakness to gain access to sensitive files on the system. By manipulating file paths, an unauthorized user could potentially identify and retrieve arbitrary files, posing a significant risk to the integrity and confidentiality of the data managed by the SCADA system. It is crucial for organizations using this software to implement mitigations to secure their installations against this threat.

Affected Version(s)

WebAccess/SCADA 9.2.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA.
.
CVE-2025-67653 : Directory Traversal Vulnerability in Advantech WebAccess/SCADA