ZeroHour

CVE-2026-73171

niche

Authenticated Arbitrary File Overwrite in Advantech EKI-1242EIMS Gateway

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Advantech EKI-1242EIMS industrial gateway firmware V1.06.01 contains an external control of file name or path flaw (CWE-73) in its backup-restore workflow, discovered by Nozomi Networks Labs. A remote attacker who already holds high-privileged (administrative) credentials can upload a crafted backup archive through the web management interface, with the archive's internal file paths not properly validated. This lets the attacker overwrite arbitrary files on the device filesystem, which the CVSS 4.0 score of 8.6 (high) reflects as high impact on the confidentiality, integrity, and availability of the device, potentially enabling persistent compromise or denial of service of the gateway. Only deployments of the EKI-1242EIMS running the affected firmware with the web interface reachable are exposed, and exploitation requires valid administrative credentials. As of now, the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation has been reported.

What to do: Restrict access to the EKI-1242EIMS web management interface to trusted management networks via firewalling or VLAN segmentation, and enforce strong, unique administrative credentials since valid high-privileged access is required to exploit this flaw. Monitor Advantech's product security advisories and upgrade to a fixed firmware release when one is published, as no fixed version is identified in the current data. Check logs for unexpected backup/restore operations and verify the integrity of files on affected devices.

Affected
Advantech EKI-1242EIMS (industrial protocol gateway)V1.06.01 (other firmware versions not specified in the available data)
Estimated exposure
nichelikely thousands to low tens of thousands of deployed units worldwide, with at most a few thousand internet-exposed web interfaces — The EKI-1242EIMS is a single-model EtherNet/IP-to-Modbus industrial gateway whose deployments are concentrated in OT networks (typically not internet-facing), and public ICS scans generally show Advantech EKI-series gateways exposed in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.

Weakness
CWE-73
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.