Canada’s Cyber Centre has issued AV26-907 for vulnerabilities affecting multiple Advantech WISE-6610 industrial gateway models. Advantech has published a security advisory covering three command-injection CVEs and directs users to updated firmware.

Key takeaways

  • The Canadian Centre for Cyber Security published control-systems advisory AV26-907 on September 10, 2026, for multiple Advantech WISE-6610 versions and models.
  • Advantech’s security advisory identifies three command-injection vulnerabilities: CVE-2026-2670, CVE-2026-79697 and CVE-2026-79698.
  • Advantech lists WISE-6610 firmware version 1.2.4, file build 20260821, on its support site; the firmware page is dated September 2, 2026.
  • Installers and operators should inventory affected gateways, restrict management-plane access, schedule the update, and validate network, VPN, LoRaWAN and application configurations after maintenance.
  • Advantech notes that upgrades from firmware 1.0.15 or earlier have additional DTB-upgrade and factory-default requirements.

Canadian advisory covers WISE-6610 gateways

The Canadian Centre for Cyber Security issued control-systems advisory AV26-907 on September 10, 2026, stating that vulnerabilities affect multiple versions and models of Advantech’s WISE-6610 industrial gateway. The advisory directs users and administrators to review the manufacturer’s information and apply needed updates.

The timing is worth separating clearly for asset-management records: Advantech’s own WISE-6610 security advisory carries a release date of September 2, 2026, while the Canadian Cyber Centre published AV26-907 on September 10. The government notice is therefore an external alert to review a manufacturer remediation that was already available.

Three command-injection CVEs are identified

Advantech’s advisory identifies CVE-2026-2670, CVE-2026-79697 and CVE-2026-79698. All three concern command-injection conditions in management-related deletion operations on the gateway rather than a radio-layer weakness in LoRaWAN itself.

CVE-2026-2670 concerns OpenVPN file-deletion handling. CVE-2026-79697 concerns certificate deletion for Basic Station. CVE-2026-79698 concerns deletion of Node-RED modules. In each case, Advantech describes a risk that a user with access to the relevant management function could cause unintended operating-system commands, alter or delete files, or affect gateway configuration, integrity or availability.

Advantech changed how deletion requests are handled

The vendor describes code changes intended to remove direct construction of shell commands from request values. For the OpenVPN issue, the remediation maps a requested file type to a fixed allowlisted path, validates the tunnel identifier and uses a filesystem API. For Basic Station certificates, requests are restricted to fixed internal certificate paths and invalid selectors are rejected.

For the Node-RED issue, Advantech says module names are validated against an allowlist, invalid names and path separators are rejected, and a requested module must match an installed module before deletion. These are meaningful changes for integrators because gateway management features commonly remain enabled after commissioning even when they are seldom used in normal operations.

Affected product list spans standard, EL and P variants

Advantech’s advisory lists WISE-6610-NB, -EB, -TB, -JB and -CB models, plus WISE-6610-EL-NB, -EL-EB, -EL-TB, -EL-JB and -EL-CB models. It also names WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA variants.

That list makes a site inventory essential. Procurement records may identify a family name or regional radio variant rather than the complete model suffix, while deployed devices can be managed by a third party. Teams should reconcile the advisory list with physical labels, device-management inventories, support contracts and the firmware currently reported by each gateway.

Firmware planning needs operational controls

Advantech’s support page lists WISE-6610 version 1.2.4 firmware, with the downloadable build identified as WISE-6610_v1.2.4_20260821. The same page says upgrades from firmware 1.0.15 or earlier require a DTB upgrade and then a factory-default reset; it cautions against restoring the original configuration in that upgrade path.

Before maintenance, operators should obtain the firmware only from Advantech’s official support channel, record the device configuration and network settings, and establish a tested rollback or recovery procedure. Because WISE-6610 deployments can combine gateway management with services such as LoRaWAN networking, Node-RED, MQTT, Modbus/TCP, VPN or edge applications, post-update testing should cover the services actually enabled at the site rather than stopping at a successful reboot.

Exposure reduction should continue during the update window

The vendor’s descriptions repeatedly refer to a user having access to an affected management function. That does not remove urgency, but it does reinforce a practical near-term priority: minimize who and what can reach the administrative interface while the update is being scheduled.

Installers and operators should restrict gateway administration to designated management networks or VPN paths, remove unnecessary port forwards, review administrative accounts and credentials, and disable unneeded functions where operationally appropriate. Logging and configuration backups should be checked before and after the change window, particularly for gateways supporting remote facilities where a failed update or configuration reset can require a site visit.

Organizations should also document completion by model, serial number, installed firmware and validation result. This produces a defensible remediation record and helps ensure that spare units, staging devices and gateways maintained by service partners are not missed.