Cyber Resilience

CVE-2016-0854

Advantech Webaccess ≤ 8.0

Public PoCHigh EPSS
Published
15 January 2016
Modified
06 May 2026
CVSS Score v3 9.8
Click a component to see what it means
Raw vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.77 99.5th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2016-0854 is a critical-severity an unspecified weakness vulnerability in Advantech Webaccess. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1105 Ingress Tool Transfer Command And Controlconfidence: HIGH
Unrestricted file upload directly enables writing arbitrary files to the target system.
T1505.003 Web Shell Persistenceconfidence: HIGH
Uploaded files can be used to deploy a web shell for persistent remote access.
T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
The vulnerability is an unrestricted upload in a public-facing web application, enabling initial access via exploitation of the exposed service.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2023-4215Same product: Advantech Webaccess
CVE-2023-2866Same product: Advantech Webaccess
CVE-2017-16720Same product: Advantech Webaccess
CVE-2025-62630Same vendor: Advantech
CVE-2021-21805Same vendor: Advantech
CVE-2023-2575Same vendor: Advantech
CVE-2023-32540Same vendor: Advantech
CVE-2023-52335Same vendor: Advantech
CVE-2025-41442Same vendor: Advantech
CVE-2025-34237Same vendor: Advantech

Affected Assets

advantech
webaccess
≤ 8.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References