Executive Summary
In November 2025, security researchers disclosed multiple critical vulnerabilities in Advantech’s DeviceOn/iEdge IoT management platform, affecting version 2.0.2 and earlier. Among the vulnerabilities were improper input handling flaws including cross-site scripting (CVE-2025-64302) and several variants of path traversal (CVE-2025-62630, CVE-2025-59171, CVE-2025-58423), which could allow remote attackers to gain unauthorized access, execute arbitrary code, trigger denial-of-service conditions, or read sensitive files. No public exploitation has been reported, but the potential risks span information leakage and remote code execution, with system-level impact possible from authenticated and unauthenticated attackers.
This incident is particularly relevant as IoT management and industrial control environments remain popular targets for exploitation of legacy systems, which often lack timely security updates. With operational continuity and data integrity at risk, organizations face mounting regulatory and business pressure to retire end-of-life products and implement robust remediation strategies.
Why This Matters Now
The continued use of unsupported and end-of-life IoT management platforms exposes critical infrastructure to escalating cyber threats. Attackers increasingly automate exploitation of such vulnerabilities, emphasizing the urgent need for enterprises to decommission vulnerable devices, segment networks, and proactively adopt modern security controls aligned to compliance frameworks.
Attack Path Analysis
The attack began with remote exploitation of unpatched vulnerabilities in the Advantech DeviceOn/iEdge platform, enabling unauthorized access to the system. Through path traversal, the attacker escalated privileges, uploading malicious configuration files to gain system-level code execution. With higher privileges, lateral movement allowed further compromise of devices and access to sensitive files. The attacker established command and control channels, potentially using covert outbound protocols to maintain system control. Sensitive data was then exfiltrated from the compromised environment using authorized or hidden outbound channels. The attack concluded with potential denial of service, data manipulation, or further disruption of critical business functions.
Kill Chain Progression
Initial Compromise
Description
Remote attacker exploited exposed web interface vulnerabilities (path traversal and XSS) to gain unauthorized access to DeviceOn/iEdge systems.
Related CVEs
CVE-2025-64302
CVSS 6.4Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.
Affected Products:
Advantech DeviceOn/iEdge – <= 2.0.2
Exploit Status:
no public exploitCVE-2025-62630
CVSS 8.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
Affected Products:
Advantech DeviceOn/iEdge – <= 2.0.2
Exploit Status:
no public exploitCVE-2025-59171
CVSS 7.5A vulnerability in a device dependency allows an unauthenticated attacker to read arbitrary files or bypass authentication.
Affected Products:
Advantech DeviceOn/iEdge – <= 2.0.2
Exploit Status:
no public exploitCVE-2025-58423
CVSS 8.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.
Affected Products:
Advantech DeviceOn/iEdge – <= 2.0.2
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Create Account
Ingress Tool Transfer
Process Injection
Data from Local System
Data Manipulation
Endpoint Denial of Service
Credentials from Password Stores
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Address Common Coding Vulnerabilities
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02
NIS2 Directive – Incident Prevention and Response Measures
Control ID: Article 21(2)(d)
DORA (Regulation (EU) 2022/2554) – ICT Systems and Tools Security
Control ID: Article 9(2)
CISA Zero Trust Maturity Model 2.0 – Implement Secure Application Development Practices
Control ID: Application Workload Pillar: Secure Development
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical vulnerabilities in Advantech DeviceOn/iEdge IoT management platform expose industrial control systems to cross-site scripting and path traversal attacks enabling remote code execution.
Information Technology/IT
CISA-designated critical infrastructure sector faces high-severity vulnerabilities allowing unauthenticated file access and system-level compromise in widely-deployed IoT management platforms across global installations.
Utilities
End-of-life IoT management systems create significant attack surface for utility infrastructure through path traversal vulnerabilities enabling denial-of-service conditions and unauthorized system access.
Manufacturing
Manufacturing operations using Advantech IoT platforms face operational disruption risks from cross-site scripting attacks causing device errors and potential data manipulation in production environments.
Sources
- Advantech DeviceOn/iEdgehttps://www.cisa.gov/news-events/ics-advisories/icsa-25-310-01Verified
- CVE-2025-64302 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-64302Verified
- CVE-2025-62630 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-62630Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, east-west traffic security, and egress policy enforcement would have restricted attacker movement and blocked malicious payload delivery and data exfiltration across every stage of this attack. Continuous visibility and real-time threat detection could have alerted defenders to anomalous activity and limited overall impact.
Control: Cloud Firewall (ACF)
Mitigation: In-line filtering would block exploit attempts and unauthenticated payloads at the perimeter.
Control: Inline IPS (Suricata)
Mitigation: Malicious file uploads and exploit traffic are identified and blocked in real time.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation prevents unauthorized east-west movement between workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound C2 traffic is filtered and anomalous communication patterns alerted.
Control: Encrypted Traffic (HPE) & Egress Security & Policy Enforcement
Mitigation: Egress filtering and encryption visibility detect and block data exfiltration attempts.
Anomalies in device behavior or system disruption trigger automated alerts and incident response.
Impact at a Glance
Affected Business Functions
- IoT Device Management
- Remote Monitoring
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive device configurations and operational data.
Recommended Actions
Key Takeaways & Next Steps
- • Immediately upgrade all legacy or end-of-life IoT management platforms to supported versions no longer affected by these vulnerabilities.
- • Enforce Zero Trust segmentation and workload isolation to ensure that compromised devices cannot pivot laterally within or across cloud environments.
- • Deploy inline IPS and cloud-native firewalls to inspect and block known exploit patterns, file traversal attempts, and suspicious inbound traffic.
- • Implement strict egress filtering and encrypted traffic visibility to restrict and monitor all outbound connections from sensitive systems.
- • Enable advanced threat detection, anomaly response, and centralized visibility to rapidly flag and contain suspicious behaviors before critical impact is realized.



