Denial of Service in Advantech ECU-1251D Affects Network Security
CVE-2026-6889

6.9MEDIUM

Key Information:

Vendor

Advantech

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-6889?

A denial of service vulnerability exists in the Advantech ECU-1251D, which can be exploited by a network-adjacent attacker. By sending a DNP3 signal to the Digital Output address, the DNP3Daemon may attempt to invoke a non-existent system file, resulting in an indefinite restart loop. Although the device retains partial accessibility through its web panel or direct signals, SCADA TelWin operators are unable to reconnect to the device until it is manually restarted, disrupting normal operations.

Affected Version(s)

ECU-1251D 08.04

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.