CVE-2026-73164
nicheAuthenticated root OS command injection in Advantech EKI-1242IEIMS web interface
Advantech EKI-1242IEIMS firmware version V1.06.01 contains a CWE-78 OS command injection flaw in its web management interface, identified by Nozomi Networks Labs. A remote attacker who already holds authenticated (high-privilege) access can send crafted request parameters to the web interface, causing the device to execute arbitrary operating system commands. Because the injected commands run as root, the attacker gains full control of the gateway, including its configuration and any traffic it bridges in the OT/industrial network. Only deployments running the affected Advantech EKI-1242IEIMS firmware with the web management interface reachable and valid admin credentials available are exposed. There is currently no evidence of exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.
What to do: Check deployed EKI-1242IEIMS units for firmware V1.06.01 and apply the vendor's fixed firmware as soon as Advantech publishes it; no fixed version is specified in the current advisory data. Until then, restrict access to the web management interface to trusted management VLANs or allowlisted admin hosts, minimize the number of accounts with admin rights, and monitor for unusual authenticated requests to the device. Since no public PoC or in-the-wild exploitation is known, remediation can be scheduled in the normal maintenance cycle but should not be deferred indefinitely.
| Advantech EKI-1242IEIMS | V1.06.01 (confirmed affected; other firmware versions unconfirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.