Vulnerability record · CVE-2016-0854 · published 15 January 2016
CVE-2016-0854: Advantech WebAccess Dashboard Viewer unrestricted file upload
Advantech · Webaccess
The uploadImageCommon function in the UploadAjaxAction script of Advantech WebAccess Dashboard Viewer fails to restrict uploaded file types, allowing arbitrary files to be written. WebAccess is an HMI/SCADA product, so this flaw matters because it can lead to code execution on industrial control system hosts.
Description
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and a high EPSS score on an ICS/SCADA product make this a critical risk.
What it is
The uploadImageCommon function in the UploadAjaxAction script of Advantech WebAccess Dashboard Viewer fails to restrict uploaded file types, allowing arbitrary files to be written. WebAccess is an HMI/SCADA product, so this flaw matters because it can lead to code execution on industrial control system hosts.
Impact
An attacker can write files of any type to the server, which typically enables uploading and executing a web shell or other malicious code with the web server's privileges.
Attack surface
Reachable over the network through the WebAccess Dashboard Viewer upload endpoint; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.77, ~99.5th percentile) and public exploit code exists (Exploit-DB 39735, Rapid7 module), so exploitation is feasible and likely observed.
What to do
- Upgrade Advantech WebAccess to version 8.1 or later, which fixes this issue.
- If immediate patching is not possible, restrict network access to the WebAccess Dashboard Viewer upload endpoint to trusted hosts only.
- Enforce file type and content validation on uploads at a reverse proxy or WAF in front of WebAccess.
- Run the WebAccess web service with least privilege and isolate it from sensitive network segments.
Detection
- Monitor the WebAccess upload directory for newly written files with executable or script extensions (e.g., .asp, .aspx, .exe, .jsp).
- Alert on POST requests to the UploadAjaxAction/uploadImageCommon endpoint from unexpected source IPs.
- Review web server logs for upload requests followed by immediate access to the uploaded file path.
- Watch for unexpected child processes spawned by the WebAccess web service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0854 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0854), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.