ZeroHour

CVE-2026-73176

niche

Authenticated OS Command Injection in Advantech EKI-1242IEIMS Web Interface

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

The web management interface of the Advantech EKI-1242IEIMS industrial gateway contains a CWE-78 OS command injection flaw in firmware version V1.06.01. A remote attacker who already holds valid, high-privileged credentials can trigger it by sending requests with specially crafted parameters to the management interface. Because the injected commands run as root, successful exploitation yields full takeover of the device, including complete confidentiality, integrity, and availability impact on the gateway itself. Any deployment running the affected firmware is exposed, though exploitation requires an authenticated account, which limits attackers to insiders or credential compromise. As of this writing the issue is not in the CISA KEV catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.

What to do: Restrict access to the EKI-1242IEIMS web management interface to trusted management networks or VPNs, enforce strong admin credentials, and monitor for unexpected requests to the management interface. Contact Advantech for patched firmware once available, since no fixed version is identified in the current data. Audit administrator accounts for compromise, as exploitation requires valid high-privileged credentials.

Affected
Advantech EKI-1242IEIMS (web management interface)V1.06.01 (other/earlier versions not specified in available data; fixed version not yet identified)
Estimated exposure
nichelikely low thousands of units worldwide (specialized industrial gateway; no public install-base or internet-scan data) — No public scan or active-install data exists for this niche Modbus/industrial gateway model; the estimate reflects typical site-level deployment of specialized OT edge hardware, usually placed behind industrial network perimeters rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.