CVE-2026-73171
nicheAuthenticated Arbitrary File Overwrite in Advantech EKI-1242EIMS Gateway
Advantech EKI-1242EIMS industrial gateway firmware V1.06.01 contains an external control of file name or path flaw (CWE-73) in its backup-restore workflow, discovered by Nozomi Networks Labs. A remote attacker who already holds high-privileged (administrative) credentials can upload a crafted backup archive through the web management interface, with the archive's internal file paths not properly validated. This lets the attacker overwrite arbitrary files on the device filesystem, which the CVSS 4.0 score of 8.6 (high) reflects as high impact on the confidentiality, integrity, and availability of the device, potentially enabling persistent compromise or denial of service of the gateway. Only deployments of the EKI-1242EIMS running the affected firmware with the web interface reachable are exposed, and exploitation requires valid administrative credentials. As of now, the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation has been reported.
What to do: Restrict access to the EKI-1242EIMS web management interface to trusted management networks via firewalling or VLAN segmentation, and enforce strong, unique administrative credentials since valid high-privileged access is required to exploit this flaw. Monitor Advantech's product security advisories and upgrade to a fixed firmware release when one is published, as no fixed version is identified in the current data. Check logs for unexpected backup/restore operations and verify the integrity of files on affected devices.
| Advantech EKI-1242EIMS (industrial protocol gateway) | V1.06.01 (other firmware versions not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.
- Weakness
- CWE-73
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.