Summary
CVE-2026-43831 is a stack-based buffer overflow (CWE-121) affecting Advantech ADAM-3600 EdgeLink. It is remotely exploitable over the network without authentication or user interaction and carries a CVSS v3.1 base score of 7.5 (HIGH), with impact limited to confidentiality. Full technical details and mitigation steps are currently restricted by the assigning authority and will be published at a later date.
Technical details
- Root cause: A stack-based buffer overflow condition (CWE-121) in the affected product.
- Trigger conditions: Reachable over the network; no privileges and no user interaction are required to trigger the flaw. The specific vulnerable component and request details remain under embargo.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N).
- Impact: High confidentiality impact (C:H); no integrity or availability impact (I:N/A:N). Per the record’s SSVC assessment, exploitation is automatable with partial technical impact and no known exploitation at time of publication.
Affected software
- Advantech ADAM-3600 EdgeLink. Exact affected version ranges have not yet been disclosed in the CVE record and are pending publication by the assigning authority.
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: No fixed version has been published in the CVE record. Monitor Advantech and the assigning authority for the forthcoming advisory and apply firmware updates as soon as they are released.
- If no patch: Minimize network exposure of the device and ensure it is not reachable from the public internet. Place the device behind a firewall, isolate it from the business network, and require secure remote-access methods (for example, a VPN) for any external connectivity.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
EdgeLink - Favicon fingerprint:
1086851975

