ZeroHour

CVE-2026-73167

niche

Authenticated root RCE via OS command injection in Advantech EKI-1242IEIMS

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Advantech EKI-1242IEIMS firmware V1.06.01 contains a CWE-78 OS command injection flaw in its web management interface, identified by Nozomi Networks Labs. An attacker who holds valid credentials can send crafted request parameters to the web interface, causing arbitrary operating system commands to be executed on the device with root privileges. Successful exploitation yields complete control of the gateway, including its configuration and any network connectivity it bridges, which is particularly significant in industrial OT environments. Only deployments of the EKI-1242IEIMS running the affected firmware are impacted, and exploitation requires authentication, limiting the attacker pool to users or anyone with compromised credentials. The issue is not listed in CISA KEV and no public proof-of-concept is known, so exploitation has not been observed.

What to do: Update the EKI-1242IEIMS to a firmware release fixed for this issue once Advantech publishes one (V1.06.01 is confirmed vulnerable). Until then, restrict the web management interface to trusted management VLANs or VPN access, minimize and rotate privileged accounts since authentication is the only barrier, and review device logs for unexpected requests or anomalous command execution tied to the web interface.

Affected
Advantech EKI-1242IEIMSfirmware V1.06.01 (other versions not confirmed in available data)
Estimated exposure
nichelikely thousands of units or fewer worldwide — This is a single-SKU industrial gateway typically deployed inside managed OT/ICS networks rather than internet-facing, no public scan data exists for the model, and exploitation requires valid credentials, so the practically affected base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.