CVE-2026-73165
nicheAuthenticated OS Command Injection in Advantech EKI-1242IEIMS Web Interface
Nozomi Networks Labs identified an OS command injection flaw (CWE-78) in the web management interface of the Advantech EKI-1242IEIMS industrial device running firmware V1.06.01. A remote attacker who already holds valid credentials can submit crafted request parameters that the interface fails to neutralize before passing to the underlying operating system, resulting in execution of arbitrary OS commands. Because the injected commands run as root, a successful attacker gains full control of the device, which in OT deployments can serve as a foothold for pivoting into industrial network segments. Exploitation requires high-privileged authentication (CVSS 4.0 PR:H), so risk concentrates on deployments with weak, default, or stolen administrative credentials. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and no exploitation has been reported.
What to do: Inventory for EKI-1242IEIMS devices running firmware V1.06.01 and contact Advantech for a patched firmware release, applying it as soon as available. Until then, restrict access to the web management interface to trusted management networks, enforce strong unique administrative credentials (change any defaults), and review device logs for unexpected authenticated requests with unusual parameter values. Network segmentation of OT zones will limit the impact of any root-level compromise.
| Advantech EKI-1242IEIMS (web management interface) | V1.06.01 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.