CVE-2026-19535
nicheCross-Site Request Forgery in Advantech EKI-1242IEIMS LuCI admin interface
CVE-2026-19535 is a Cross-Site Request Forgery (CWE-352) flaw in the LuCI administrative web interface of the Advantech EKI-1242IEIMS running firmware V1.06.01, identified by Nozomi Networks Labs. A remote unauthenticated attacker can trigger it by inducing the browser of a logged-in administrator to submit unauthorized state-changing requests to the device's management interface, typically via a malicious page or link visited while the admin session is active. Successful exploitation grants the attacker the ability to invoke privileged management functions as the administrator, which per the CVSS 4.0 score (8.6 High) can compromise the confidentiality, integrity, and availability of the device. Only operators of the Advantech EKI-1242IEIMS running the affected firmware are exposed, and the attack requires user interaction from an authenticated administrator. As of this analysis, the issue is not listed in CISA KEV, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.
What to do: Contact Advantech or check its support portal for a firmware release that fixes this CSRF issue, as no fixed version is specified in the available data. Until patched, restrict access to the LuCI management interface to trusted OT network segments or VPN (block direct internet exposure), and have administrators close LuCI sessions before browsing untrusted websites. Review device configuration logs for unexpected or unauthorized management changes.
| Advantech EKI-1242IEIMS (LuCI administrative web interface) | V1.06.01 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.
- Weakness
- CWE-352
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.