CVE-2026-2670 is an OS command injection vulnerability in Advantech WISE-6610 and WISE-6610P cellular-router firmware version 1.2.1_20251110. The Background Management OpenVPN configuration deletion functionality insufficiently validates the user-controlled delete_file argument before incorporating it into an operating-system command. An attacker can manipulate this argument to inject and execute arbitrary shell commands. The issue affects WISE-6610-NB, -EB, -TB, -JB, -CB, their EL variants, and WISE-6610P-DEA, -DNA, and -DTA models.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Python proof-of-concept exploit for CVE-2026-2670 targeting Advantech WISE-6610 industrial cellular routers. Structure: (1) README.md documents the vulnerability, requirements, and usage; (2) exploit-cve-2026-2670.py is the sole code file and entry point. Core capability: authenticated remote command execution via command injection in the LuCI OpenVPN management endpoint `/cgi-bin/luci/admin/openvpn_apply`. The script either (a) logs in by first fetching `luci_nonce` from `/cgi-bin/luci/` and then POSTing credentials to the same path to obtain a `sysauth` cookie, or (b) accepts a pre-authenticated `sysauth` cookie. It then sends a POST request with parameters `act=delete`, `openvpn_id=1`, and a crafted `delete_file` value of the form `123123|<command>; echo$(IFS)` to execute arbitrary shell commands (README claims root privileges). Post-exploitation behavior: the PoC does not implement an interactive shell; instead it expects the operator-supplied command to redirect output to a web-accessible file (e.g., `id > output.txt`) and then performs an HTTP GET to the user-specified output path (e.g., `/output.txt`) after a configurable delay to display results. The script includes optional verbose debug logging of request/response headers, cookies, and response snippets, and disables TLS verification warnings (verify=False), indicating it is intended for testing devices with self-signed certificates.
Repository contains a Python proof-of-concept exploit for CVE-2026-2670 targeting Advantech WISE-6610 industrial cellular router’s LuCI web interface. Structure is minimal (2 files): (1) README.md describing the vulnerability, requirements, and usage; (2) exploit-cve-2026-2670.py implementing the exploit. Core capability: authenticated remote command execution via command injection in the OpenVPN deletion handler. The script either (a) logs in with provided credentials by first fetching a luci_nonce cookie from GET /cgi-bin/luci/ and then POSTing luci_username/luci_password to /cgi-bin/luci/ to obtain a sysauth cookie, or (b) accepts a pre-authenticated sysauth cookie. It then sends a POST to /cgi-bin/luci/admin/openvpn_apply with act=delete, openvpn_id=1, and a crafted delete_file value of the form 123123|<command>; echo$(IFS), leveraging shell metacharacters to execute arbitrary commands (described as root). Finally, after a configurable delay, it attempts to retrieve the command output by HTTP GET to a user-specified output path (e.g., /output.txt), assuming the injected command wrote output into a web-accessible location. Notable operational details: disables TLS verification warnings (verify=False), supports debug logging of headers/cookies/response snippets, and relies on file-based output retrieval rather than an interactive shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remotely exploitable OS command-injection vulnerability in the Background Management component of Advantech WISE-6610 version 1.2.1_20251110. An attacker can manipulate the delete_file argument to the OpenVPN-apply CGI endpoint (/cgi-bin/luci/admin/openvpn_apply) to execute operating-system commands.
Remote OS command injection in Advantech WISE-6610 via manipulation of the 'delete_file' argument in /cgi-bin/luci/admin/openvpn_apply (Background Management component).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.