Vulnerabilities in Advantech ECU-1251D Products
31 July 2026
CSA has issued 2 CVE IDs to the vulnerabilities reported in Advantech Products as part of CSA’s Responsibility Vulnerability Disclosure Policy. Users and administrators of the affected product versions are advised to update to the latest version immediately.
Background
CSA has issued 2 CVE IDs (CVE-2026-6889 and CVE-2026-6890) for the vulnerabilities reported in Advantech’s industrial communication gateway product, ECU-1251D. Attackers may exploit the vulnerabilities to conduct denial-of-service or gain unauthorised access to the product. The product owner, Advantech, has released a security update to address them.
Impact
CVE-2026-6889: Successful exploitation of this vulnerability could allow an attacker to conduct a denial-of-service attack and modify the parameters of the product. This vulnerability has a Common Vulnerability Scoring System (CVSS v4.0) score of 6.9 out of 10.
CVE-2026-6890: Successful exploitation of this vulnerability could allow an attacker to gain unauthorised access to the product due to the use of default configuration. This vulnerability has a Common Vulnerability Scoring System (CVSS v4.0) score of 7.1 out of 10.
Affected Products
The vulnerabilities affect Advantech ECU-1251D products with EdgeLink versions prior to 2.8.5.0.
Mitigation
Users and administrators of affected product versions are advised to update to the latest version immediately.
Special Thanks to:
Informer: CSIRT NASK and WOT
Product Owner: Advantech
