CVE-2026-73163
nicheAuthenticated root OS command injection in Advantech EKI-1242IEIMS firmware
Nozomi Networks Labs identified an OS command injection flaw (CWE-78) in the web management interface of the Advantech EKI-1242IEIMS industrial device. Firmware version V1.06.01 fails to properly neutralize special elements in request parameters, so a remote attacker who holds valid web-interface credentials can submit crafted parameter values that are executed by the underlying operating system. Successful exploitation yields arbitrary OS command execution with root privileges, meaning full compromise of the device, including its configuration and network position. Any organization running the affected firmware, typically in OT/industrial deployments, is exposed, with authentication being the main barrier to attack. The vulnerability is not listed in CISA KEV, no public proof-of-concept is known, and no exploitation has been observed in the wild.
What to do: Update EKI-1242IEIMS devices to the latest firmware available from Advantech, ensuring it is newer than V1.06.01 (the data does not name a specific fixed version, so confirm with the vendor's advisory). Until patched, restrict access to the web management interface to trusted management networks or VPNs, enforce strong credentials for all authenticated accounts, and review device logs for unexpected or suspicious authenticated sessions. Monitor the Nozomi Networks and Advantech advisories for fixes and for any additions to the affected-version list.
| Advantech EKI-1242IEIMS (web management interface) | firmware V1.06.01 (version identified in the advisory; status of other versions not stated in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.