Cyber Resilience

CVE-2016-0854

Advantech Webaccess ≤ 8.0

Public PoCHigh EPSS
Published
15 January 2016
Modified
06 May 2026
CVSS Score v3 9.8
Click a component to see what it means
Raw vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.77 99.5th percentile
Risk Priority 97 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2016-0854 is a critical-severity an unspecified weakness vulnerability in Advantech Webaccess. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

CWE(s)

Related Threats

CVEs Like This One

CVE-2017-16720Same product: Advantech Webaccess
CVE-2023-2866Same product: Advantech Webaccess
CVE-2023-4215Same product: Advantech Webaccess
CVE-2023-52335Same vendor: Advantech
CVE-2024-37187Same vendor: Advantech
CVE-2025-53509Same vendor: Advantech
CVE-2024-28948Same vendor: Advantech
CVE-2024-50361Same vendor: Advantech
CVE-2023-3256Same vendor: Advantech
CVE-2025-53475Same vendor: Advantech

Affected Assets

advantech
webaccess
≤ 8.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References