CVE-2026-73173
nicheMissing Authentication in Advantech EKI-1242EIMS Management Protocol (TCP 5058)
The edgserver management protocol of the Advantech EKI-1242EIMS firmware version V1.06.01 performs no authentication for critical device-management functions (CWE-306). A remote, unauthenticated attacker can trigger these functions simply by sending crafted requests to TCP port 5058, gaining the ability to reconfigure the device's network settings, reboot or factory-reset it, and push a firmware upgrade. This effectively gives an attacker full administrative control over the device without any credentials, enabling denial of service, disruption of the network path the gateway manages, and potential implantation of malicious firmware. Any organization running the EKI-1242EIMS on the affected firmware is exposed, particularly where TCP port 5058 is reachable from untrusted networks. As of publication there is no evidence of exploitation in the wild, the issue is not in CISA's KEV catalog, and no public proof-of-concept is known; the flaw was identified by Nozomi Networks Labs.
What to do: Inventory for EKI-1242EIMS devices and verify the firmware version, treating V1.06.01 as vulnerable. Immediately restrict access to TCP port 5058 with firewall rules or ACLs so only trusted management hosts can reach it, and never expose this port to the internet or flat IT networks. Contact Advantech for a patched firmware release and apply it as soon as available; until then, monitor the device for unexpected reboots, configuration changes, or firmware updates.
| Advantech EKI-1242EIMS | Firmware V1.06.01 (only version confirmed vulnerable in the available data; check with the vendor for other affected versions and fixed releases) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.