ZeroHour

CVE-2026-73165

niche

Authenticated OS Command Injection in Advantech EKI-1242IEIMS Web Interface

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Nozomi Networks Labs identified an OS command injection flaw (CWE-78) in the web management interface of the Advantech EKI-1242IEIMS industrial device running firmware V1.06.01. A remote attacker who already holds valid credentials can submit crafted request parameters that the interface fails to neutralize before passing to the underlying operating system, resulting in execution of arbitrary OS commands. Because the injected commands run as root, a successful attacker gains full control of the device, which in OT deployments can serve as a foothold for pivoting into industrial network segments. Exploitation requires high-privileged authentication (CVSS 4.0 PR:H), so risk concentrates on deployments with weak, default, or stolen administrative credentials. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and no exploitation has been reported.

What to do: Inventory for EKI-1242IEIMS devices running firmware V1.06.01 and contact Advantech for a patched firmware release, applying it as soon as available. Until then, restrict access to the web management interface to trusted management networks, enforce strong unique administrative credentials (change any defaults), and review device logs for unexpected authenticated requests with unusual parameter values. Network segmentation of OT zones will limit the impact of any root-level compromise.

Affected
Advantech EKI-1242IEIMS (web management interface)V1.06.01
Estimated exposure
nichelikely on the order of thousands of deployed units at industrial sites worldwide (no public install counts or scan data available for this specific model) — The EKI-1242IEIMS is a niche Advantech industrial OT device typically deployed at industrial facilities rather than consumer environments, so exposure is estimated from typical deployment patterns of specialized industrial gateways, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.