The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.
https://www.cisa.gov/news-events/ics-advisories/icsa-14-198-02
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-2404