ZeroHour

CVE-2026-73163

niche

Authenticated root OS command injection in Advantech EKI-1242IEIMS firmware

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Nozomi Networks Labs identified an OS command injection flaw (CWE-78) in the web management interface of the Advantech EKI-1242IEIMS industrial device. Firmware version V1.06.01 fails to properly neutralize special elements in request parameters, so a remote attacker who holds valid web-interface credentials can submit crafted parameter values that are executed by the underlying operating system. Successful exploitation yields arbitrary OS command execution with root privileges, meaning full compromise of the device, including its configuration and network position. Any organization running the affected firmware, typically in OT/industrial deployments, is exposed, with authentication being the main barrier to attack. The vulnerability is not listed in CISA KEV, no public proof-of-concept is known, and no exploitation has been observed in the wild.

What to do: Update EKI-1242IEIMS devices to the latest firmware available from Advantech, ensuring it is newer than V1.06.01 (the data does not name a specific fixed version, so confirm with the vendor's advisory). Until patched, restrict access to the web management interface to trusted management networks or VPNs, enforce strong credentials for all authenticated accounts, and review device logs for unexpected or suspicious authenticated sessions. Monitor the Nozomi Networks and Advantech advisories for fixes and for any additions to the affected-version list.

Affected
Advantech EKI-1242IEIMS (web management interface)firmware V1.06.01 (version identified in the advisory; status of other versions not stated in the available data)
Estimated exposure
nichelikely on the order of thousands of devices at most worldwide (niche industrial model) — No public install counts or internet-scan figures exist for this specific model; Advantech EKI-series devices are deployed in limited numbers in OT/industrial networks, often behind firewalls rather than mass-market or broadly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.