ZeroHour

CVE-2026-73166

niche

Authenticated Code Injection in Advantech EKI-1242IEIMS Web Interface (Root RCE)

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Nozomi Networks Labs identified a CWE-94 code injection flaw in the web management interface of the Advantech EKI-1242IEIMS running firmware V1.06.01. A remote attacker who is already authenticated with high-privilege (administrator-level) access to the web interface can inject and execute arbitrary code, including operating-system commands that run as root. Successful exploitation yields full control of the device, with high impact on its confidentiality, integrity and availability (CVSS 4.0 score 8.6 High). Only deployments of EKI-1242IEIMS on the affected firmware are exposed, and the attack requires valid administrative credentials, which lowers the practical risk compared with unauthenticated flaws. The issue is not listed in CISA KEV, no public proof-of-concept is known, and no exploitation has been reported in the wild.

What to do: Inventory deployed EKI-1242IEIMS units and check the firmware version; units on V1.06.01 should be updated to the latest firmware from Advantech once a fixed release is published. In the meantime, restrict access to the web management interface to trusted management networks or VPN and audit which accounts hold high-privilege credentials, since exploitation requires authenticated administrator access. Monitor Advantech and Nozomi Networks advisories for patch availability and any added indicators of compromise.

Affected
Advantech EKI-1242IEIMS (web management interface)Firmware V1.06.01 (version confirmed affected by Nozomi Networks Labs; status of other versions not stated)
Estimated exposure
nicheunknown — plausibly hundreds to a few thousand deployed units in industrial environments — No public install-base or internet-exposure scan data is available for this specific niche Advantech industrial device, so the estimate reflects the typical deployment volumes of specialized industrial gateways rather than measured counts.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.

Weakness
CWE-94
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.