Advantech WISE-6610 Series Node-RED Command Injection (CVE-2026-79698)
First seen Sep 9, 2026 · Updated Sep 9, 2026 · CVSS 9.9
A critical command injection vulnerability affects multiple Advantech WISE-6610 industrial cellular gateway models running firmware 1.2.1_20251110, exploitable remotely via the Node-RED Library's nodered_lib_apply function. Public exploit code is available, significantly increasing the likelihood of active exploitation against exposed industrial and IoT gateway deployments. Advantech has released a patched firmware version (1.2.4_20260821) to address the flaw.
Technical Analysis
The vulnerability resides in the nodered_lib_apply function of the Node-RED Library component embedded in WISE-6610 series gateways, where insufficient sanitization of the 'act' argument allows an attacker to inject arbitrary OS commands. Given the CVSS score of 9.9, the flaw likely requires minimal privileges and no user interaction, enabling unauthenticated or low-privilege remote attackers to achieve full command execution on the device. As these gateways are commonly used to bridge cellular/edge networks with industrial control and monitoring systems, successful exploitation could provide a foothold for lateral movement into OT/IT environments. If such gateways are used as edge nodes feeding sensor or telemetry data into RAG pipelines or AI-driven monitoring/agent systems, a compromised device could inject malicious or manipulated data upstream, or expose API keys and credentials used by automation agents interacting with the gateway's management interface, warranting agent-relevant risk consideration. Organizations should treat this as a high-priority patch given the public availability of exploit code.
Affected Systems
Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA, WISE-6610P-DTA — all running firmware version 1.2.1_20251110
Indicators of Compromise
- N/A - no specific hashes, IPs, or domains published; monitor for anomalous Node-RED process spawning, unexpected shell commands, or unauthorized configuration changes on WISE-6610 devices
Remediation Steps
- 1
Upgrade firmware
Update all affected WISE-6610 series devices to firmware version 1.2.4_20260821 or later as released by Advantech.
- 2
Restrict network exposure
Ensure WISE-6610 management interfaces and Node-RED services are not exposed to the public internet; restrict access via VPN, firewall rules, or network segmentation.
- 3
Disable unused Node-RED functionality
If Node-RED Library features are not required, disable or restrict access to the nodered_lib_apply function and related endpoints.
- 4
Monitor for exploitation
Review device logs for unusual command execution, unexpected process activity, or configuration changes indicative of exploitation attempts.
- 5
Credential rotation
Rotate any API keys, credentials, or tokens accessible from or stored on affected gateways, particularly those used by automation, monitoring, or AI agent integrations.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.