CVE-2025-34243 | Advantech WebAccess/VPN up to 1.1.4 Search Parameter AjaxFwRulesController.ajaxNetworkFwRulesAction sql injection
A vulnerability described as critical has been identified in Advantech WebAccess and VPN up to 1.1.4. This impacts the function AjaxFwRulesController.ajaxNetworkFwRulesAction of the component Search Parameter Handler. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2025-34243. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.