CVE-2025-34241 | Advantech WebAccess/VPN up to 1.1.4 Search Parameter AjaxDeviceController.ajaxDeviceAction sql injection (EUVD-2025-38165)
A vulnerability labeled as critical has been found in Advantech WebAccess and VPN up to 1.1.4. The impacted element is the function AjaxDeviceController.ajaxDeviceAction of the component Search Parameter Handler. The manipulation results in sql injection.
This vulnerability is cataloged as CVE-2025-34241. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.