Summary
CVE-2026-43832 is a stack-based buffer overflow in the Advantech ADAM-3600 EdgeLink remote terminal unit that allows an unauthenticated attacker to execute arbitrary code. The flaw resides in the device’s HTTP Cookie parsing routines and is reachable over the network when the SafeEnhancement feature is enabled. It affects EdgeLink versions prior to 2.8.5.1 and is rated critical severity.
Technical details
- Root cause: A stack-based buffer overflow in the Cookie parsing methods of the ADAM-3600 EdgeLink software.
- Trigger conditions: Exploitable when the SafeEnhancement feature is enabled; no authentication is required.
- Attack vector: Network — an attacker sends a crafted HTTP request with a malicious Cookie header to the exposed device.
- Impact: Successful exploitation leads to arbitrary code execution, compromising the confidentiality, integrity, and availability of the affected device.
Affected software
- Advantech ADAM-3600 EdgeLink: all versions prior to 2.8.5.1
Severity
- CVSS 4.0 base score: 9.2 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Update Advantech ADAM-3600 EdgeLink to version 2.8.5.1 or later.
- If no patch can be applied: Minimize network exposure of the device and ensure it is not reachable from the internet. Place the device behind a firewall and isolate it from business networks. Where remote access is required, use secure methods such as a VPN. Consider disabling the SafeEnhancement feature where operationally feasible to remove the exploitable code path.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
EdgeLink - Favicon fingerprint:
1086851975

