CVE-2026-6889 Details
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
A denial-of-service vulnerability exists in the Advantech ECU-1251D industrial communication gateway, specifically in devices running EdgeLink versions prior to 2.8.5.0. The vulnerability allows a network-adjacent attacker to send a DNP3 signal to the Digital Output address, causing the DNP3Daemon to reference a non-existent system file and enter an endless restart loop. Although the device remains partially accessible through its web panel or direct signals, operators using SCADA TelWin cannot reconnect until the device is manually restarted.
Users and administrators are advised to update to the latest version immediately.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Rejected | CSA |
| Jul 31, 2026 | CVE Modified | CSA |
| Jul 31, 2026 | New CVE Received | CSA |