ZeroHour

CVE-2026-73177

niche

Unsigned Firmware Update Flaw in Advantech EKI-1242EIMS Industrial Device

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

The Advantech EKI-1242EIMS at firmware version V1.06.01 does not cryptographically verify firmware images during the update process, an insufficient verification of data authenticity flaw (CWE-345) identified by Nozomi Networks Labs. An attacker who is already authenticated as an administrator can upload a modified firmware image through the device's web management interface, and the device installs it without any signature or certificate check. Successful exploitation yields full, persistent compromise of the platform, since the attacker-controlled firmware remains resident on the device. Organizations running the EKI-1242EIMS, typically in industrial and OT deployments, are affected; the requirement for administrator-level credentials means risk is highest where such credentials could be stolen, reused, or abused by insiders. No public proof-of-concept is known, the vulnerability is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Upgrade the EKI-1242EIMS to a fixed firmware release from Advantech as soon as one is published (V1.06.01 is the version confirmed affected; check the vendor advisory for the patched build). Until then, restrict web management access to trusted administrative hosts, segment the device from untrusted networks, and only flash firmware obtained directly from official Advantech sources. Audit administrator credentials and review devices for signs of unauthorized firmware changes.

Affected
Advantech EKI-1242EIMSV1.06.01 (firmware version identified in the advisory; no other version ranges were provided)
Estimated exposure
nichelikely on the order of thousands of deployed units worldwide; no reliable public exposure counts — The EKI-1242EIMS is a specialized Advantech industrial IoT device typically deployed inside segmented OT networks rather than at consumer scale, so affected installations are plausibly in the thousands and internet-exposed counts likely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.

Weakness
CWE-345
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.