CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It involves a SQL injection risk.
CVE
CVE-2025-34243
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
Original NVD Description
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
Related CVEs
Other vulnerabilities affecting the same vendor(s)