CVE-2025-34242 | Advantech WebAccess/VPN up to 1.1.4 Search Parameter AjaxNetworkController.ajaxAction sql injection
A vulnerability marked as critical has been reported in Advantech WebAccess and VPN up to 1.1.4. This affects the function AjaxNetworkController.ajaxAction of the component Search Parameter Handler. This manipulation causes sql injection.
This vulnerability is registered as CVE-2025-34242. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.