ZeroHour

CVE-2026-73172

niche

Unauthenticated Root OS Command Injection in Advantech EKI-1242EIMS

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

Advantech's EKI-1242EIMS edge gateway, in firmware version V1.06.01, contains an OS command injection flaw (CWE-78) in its edgserver management service. A remote, unauthenticated attacker can send specially crafted requests to TCP port 5058 to inject and execute arbitrary operating system commands on the device. Because the injected commands run with root privileges, a successful exploit gives the attacker full control of the gateway, which is typically positioned to bridge IT and OT/industrial network segments. Any deployed EKI-1242EIMS running firmware V1.06.01 is affected, particularly units where port 5058 is reachable from untrusted networks. No exploitation in the wild, public proof-of-concept code, or KEV listing is known as of this analysis.

What to do: Check deployed EKI-1242EIMS devices and upgrade to a firmware version newer than V1.06.01 as soon as Advantech publishes a fix. In the meantime, restrict access to TCP port 5058 with firewall/ACL rules so only trusted management hosts can reach it, and review logs for unexpected connections to that port. Treat any gateway exposed to the internet on port 5058 as high priority to remediate, given the pre-authentication, root-level nature of the flaw.

Affected
Advantech EKI-1242EIMS (edgserver management service)firmware V1.06.01
Estimated exposure
nicheunknown — likely on the order of thousands of deployed units at most, with only a subset exposing TCP port 5058 to the internet — No public install-base or internet-exposure scan data exists for this specific Advantech gateway model; EKI-series industrial gateways are niche OT devices usually deployed inside industrial networks, so only a fraction are directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.