CVE-2026-73170
nicheAuthenticated Lua Code Injection in Advantech EKI-1242EIMS Modbus CSV Import
Advantech EKI-1242EIMS firmware version V1.06.01 contains a CWE-94 code injection flaw in the device's Modbus CSV import workflow. An attacker who holds valid, high-privileged credentials can upload a crafted CSV file through the import function, causing the gateway to execute arbitrary Lua code embedded in the file. Successful exploitation yields full confidentiality, integrity, and availability impact on the device, meaning an attacker could take control of the gateway and potentially manipulate the Modbus communications it brokers in an industrial network. Any deployment of EKI-1242EIMS running V1.06.01 with users who can access the CSV import feature is affected, with the practical barrier being the need for an authenticated account. As of now, the vulnerability is not in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation has been observed in the wild.
What to do: Check with Advantech for a firmware release newer than V1.06.01 that addresses the Modbus CSV import code injection and apply it when available. Until then, restrict the device's management interface to trusted administrative users on a segmented OT network, never expose the gateway directly to the internet, and audit accounts that can perform CSV imports. Nozomi Networks Labs' advisory is the source for details; monitor OT traffic for unexpected Lua/script-related device behavior.
| Advantech EKI-1242EIMS (Modbus gateway) | V1.06.01 (version confirmed by Nozomi Networks Labs; other versions not stated in the advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.
- Weakness
- CWE-94
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.