ZeroHour

CVE-2026-73173

niche

Missing Authentication in Advantech EKI-1242EIMS Management Protocol (TCP 5058)

CVSS 4.0
8.8 high
EPSS
Published
()
Modified
AI analysis

The edgserver management protocol of the Advantech EKI-1242EIMS firmware version V1.06.01 performs no authentication for critical device-management functions (CWE-306). A remote, unauthenticated attacker can trigger these functions simply by sending crafted requests to TCP port 5058, gaining the ability to reconfigure the device's network settings, reboot or factory-reset it, and push a firmware upgrade. This effectively gives an attacker full administrative control over the device without any credentials, enabling denial of service, disruption of the network path the gateway manages, and potential implantation of malicious firmware. Any organization running the EKI-1242EIMS on the affected firmware is exposed, particularly where TCP port 5058 is reachable from untrusted networks. As of publication there is no evidence of exploitation in the wild, the issue is not in CISA's KEV catalog, and no public proof-of-concept is known; the flaw was identified by Nozomi Networks Labs.

What to do: Inventory for EKI-1242EIMS devices and verify the firmware version, treating V1.06.01 as vulnerable. Immediately restrict access to TCP port 5058 with firewall rules or ACLs so only trusted management hosts can reach it, and never expose this port to the internet or flat IT networks. Contact Advantech for a patched firmware release and apply it as soon as available; until then, monitor the device for unexpected reboots, configuration changes, or firmware updates.

Affected
Advantech EKI-1242EIMSFirmware V1.06.01 (only version confirmed vulnerable in the available data; check with the vendor for other affected versions and fixed releases)
Estimated exposure
nicheunknown; plausibly low thousands of deployed units, with only a fraction exposing TCP 5058 to untrusted networks — The EKI-1242EIMS is a niche industrial gateway with no published active-install counts or public internet-exposure scan data, so any total is a rough guess based on the typical small installed base of such devices and common OT practice of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.

Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.