Summary
CVE-2026-43829 is a stack-based buffer overflow (CWE-121) in the Advantech ADAM-3600 EdgeLink remote terminal unit. An unauthenticated, network-based attacker can exploit the flaw in the product’s password functionality to achieve code execution when the SafeEnhancement feature is enabled. The issue affects EdgeLink versions prior to 2.8.5.1 and carries a CVSS v3.1 base score of 7.5 (HIGH).
Technical details
- Root cause: A stack-based buffer overflow (CWE-121) in the password functionality of the ADAM-3600 EdgeLink.
- Trigger conditions: Exploitable when the SafeEnhancement feature is enabled; no authentication or user interaction is required.
- Attack vector: Network (remotely reachable service).
- Impact: Successful exploitation could allow an unauthenticated attacker to conduct code execution on the affected device.
Affected software
- Advantech ADAM-3600 EdgeLink — all versions prior to 2.8.5.1.
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Update the ADAM-3600 EdgeLink to version 2.8.5.1 or later, as released by Advantech.
- If no patch can be applied: Minimize network exposure of the device, ensuring it is not directly reachable from the internet. Place control-system devices behind firewalls and isolate them from business networks; when remote access is required, use secure methods such as a VPN. Where operationally feasible, review whether the SafeEnhancement feature must remain enabled, since exploitation is described as requiring it.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
EdgeLink - Favicon fingerprint:
1086851975

