← Vulnerability feed

Vulnerability record · CVE-2016-0854 · published 15 January 2016

CVE-2016-0854: Advantech WebAccess Dashboard Viewer unrestricted file upload

Advantech · Webaccess

The uploadImageCommon function in the UploadAjaxAction script of Advantech WebAccess Dashboard Viewer fails to restrict uploaded file types, allowing arbitrary files to be written. WebAccess is an HMI/SCADA product, so this flaw matters because it can lead to code execution on industrial control system hosts.

9.8 CVSS 3.0 Critical EPSS 77% · top 0.5%
9.8CVSS 3.0 base score, v2 10.0
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and a high EPSS score on an ICS/SCADA product make this a critical risk.

What it is

The uploadImageCommon function in the UploadAjaxAction script of Advantech WebAccess Dashboard Viewer fails to restrict uploaded file types, allowing arbitrary files to be written. WebAccess is an HMI/SCADA product, so this flaw matters because it can lead to code execution on industrial control system hosts.

Impact

An attacker can write files of any type to the server, which typically enables uploading and executing a web shell or other malicious code with the web server's privileges.

Attack surface

Reachable over the network through the WebAccess Dashboard Viewer upload endpoint; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.77, ~99.5th percentile) and public exploit code exists (Exploit-DB 39735, Rapid7 module), so exploitation is feasible and likely observed.

What to do

  • Upgrade Advantech WebAccess to version 8.1 or later, which fixes this issue.
  • If immediate patching is not possible, restrict network access to the WebAccess Dashboard Viewer upload endpoint to trusted hosts only.
  • Enforce file type and content validation on uploads at a reverse proxy or WAF in front of WebAccess.
  • Run the WebAccess web service with least privilege and isolate it from sensitive network segments.

Detection

  • Monitor the WebAccess upload directory for newly written files with executable or script extensions (e.g., .asp, .aspx, .exe, .jsp).
  • Alert on POST requests to the UploadAjaxAction/uploadImageCommon endpoint from unexpected source IPs.
  • Review web server logs for upload requests followed by immediate access to the uploaded file path.
  • Watch for unexpected child processes spawned by the WebAccess web service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0854 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-9208Advantech webaccess memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code v…EPSS 9.3%9.8CVE-2021-33023Advantech webaccess heap-based buffer overflow vulnerabilityAdvantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.EPSS 2.3%9.8CVE-2021-38389Advantech webaccess stack-based buffer overflow vulnerabilityAdvantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.EPSS 10%9.8CVE-2021-38408Advantech webaccess stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of use…EPSS 12%9.8CVE-2020-12019Advantech webaccess stack-based buffer overflow vulnerabilityWebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.EPSS 2.2%9.8CVE-2020-10638Advantech webaccess heap-based buffer overflow vulnerabilityAdvantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of prope…EPSS 7.1%9.8CVE-2020-12002Advantech webaccess stack-based buffer overflow vulnerabilityAdvantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of prop…EPSS 9.1%9.8CVE-2020-12006Advantech webaccess relative path traversal vulnerabilityAdvantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privile…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2016-0854), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.