ZeroHour

CVE-2026-19535

niche

Cross-Site Request Forgery in Advantech EKI-1242IEIMS LuCI admin interface

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-19535 is a Cross-Site Request Forgery (CWE-352) flaw in the LuCI administrative web interface of the Advantech EKI-1242IEIMS running firmware V1.06.01, identified by Nozomi Networks Labs. A remote unauthenticated attacker can trigger it by inducing the browser of a logged-in administrator to submit unauthorized state-changing requests to the device's management interface, typically via a malicious page or link visited while the admin session is active. Successful exploitation grants the attacker the ability to invoke privileged management functions as the administrator, which per the CVSS 4.0 score (8.6 High) can compromise the confidentiality, integrity, and availability of the device. Only operators of the Advantech EKI-1242IEIMS running the affected firmware are exposed, and the attack requires user interaction from an authenticated administrator. As of this analysis, the issue is not listed in CISA KEV, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.

What to do: Contact Advantech or check its support portal for a firmware release that fixes this CSRF issue, as no fixed version is specified in the available data. Until patched, restrict access to the LuCI management interface to trusted OT network segments or VPN (block direct internet exposure), and have administrators close LuCI sessions before browsing untrusted websites. Review device configuration logs for unexpected or unauthorized management changes.

Affected
Advantech EKI-1242IEIMS (LuCI administrative web interface)V1.06.01
Estimated exposure
nicheunknown precisely; plausibly on the order of thousands of units at most — This is a single-SKU industrial gateway deployed in OT/ICS environments rather than a mass-market consumer product, and no public install-base or internet-exposure scan data is available for this model.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.

Weakness
CWE-352
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.