CVE-2025-34244 | Advantech WebAccess/VPN up to 1.1.4 Search Parameter AjaxFwRulesController.ajaxDeviceFwRulesAction sql injection
A vulnerability classified as critical has been found in Advantech WebAccess and VPN up to 1.1.4. Affected is the function AjaxFwRulesController.ajaxDeviceFwRulesAction of the component Search Parameter Handler. Performing manipulation results in sql injection.
This vulnerability is reported as CVE-2025-34244. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.