CVE-2025-34240 | Advantech WebAccess/VPN up to 1.1.4 Search Parameter AppManagementController.appUpgradeAction sql injection
A vulnerability identified as critical has been detected in Advantech WebAccess and VPN up to 1.1.4. The affected element is the function AppManagementController.appUpgradeAction of the component Search Parameter Handler. The manipulation leads to sql injection.
This vulnerability is listed as CVE-2025-34240. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.