ZeroHour

CVE-2026-73170

niche

Authenticated Lua Code Injection in Advantech EKI-1242EIMS Modbus CSV Import

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Advantech EKI-1242EIMS firmware version V1.06.01 contains a CWE-94 code injection flaw in the device's Modbus CSV import workflow. An attacker who holds valid, high-privileged credentials can upload a crafted CSV file through the import function, causing the gateway to execute arbitrary Lua code embedded in the file. Successful exploitation yields full confidentiality, integrity, and availability impact on the device, meaning an attacker could take control of the gateway and potentially manipulate the Modbus communications it brokers in an industrial network. Any deployment of EKI-1242EIMS running V1.06.01 with users who can access the CSV import feature is affected, with the practical barrier being the need for an authenticated account. As of now, the vulnerability is not in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation has been observed in the wild.

What to do: Check with Advantech for a firmware release newer than V1.06.01 that addresses the Modbus CSV import code injection and apply it when available. Until then, restrict the device's management interface to trusted administrative users on a segmented OT network, never expose the gateway directly to the internet, and audit accounts that can perform CSV imports. Nozomi Networks Labs' advisory is the source for details; monitor OT traffic for unexpected Lua/script-related device behavior.

Affected
Advantech EKI-1242EIMS (Modbus gateway)V1.06.01 (version confirmed by Nozomi Networks Labs; other versions not stated in the advisory)
Estimated exposure
nichelikely in the low thousands of units deployed worldwide, mostly inside closed OT/ICS networks rather than internet-exposed — order-of-magnitude estimate — The EKI-1242EIMS is a specialized industrial Modbus protocol gateway, a niche product line typically deployed in segmented industrial networks; no public install-base or internet-exposed scan count is available, so this rests on the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.

Weakness
CWE-94
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.