CVE-2026-73177
nicheUnsigned Firmware Update Flaw in Advantech EKI-1242EIMS Industrial Device
The Advantech EKI-1242EIMS at firmware version V1.06.01 does not cryptographically verify firmware images during the update process, an insufficient verification of data authenticity flaw (CWE-345) identified by Nozomi Networks Labs. An attacker who is already authenticated as an administrator can upload a modified firmware image through the device's web management interface, and the device installs it without any signature or certificate check. Successful exploitation yields full, persistent compromise of the platform, since the attacker-controlled firmware remains resident on the device. Organizations running the EKI-1242EIMS, typically in industrial and OT deployments, are affected; the requirement for administrator-level credentials means risk is highest where such credentials could be stolen, reused, or abused by insiders. No public proof-of-concept is known, the vulnerability is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Upgrade the EKI-1242EIMS to a fixed firmware release from Advantech as soon as one is published (V1.06.01 is the version confirmed affected; check the vendor advisory for the patched build). Until then, restrict web management access to trusted administrative hosts, segment the device from untrusted networks, and only flash firmware obtained directly from official Advantech sources. Audit administrator credentials and review devices for signs of unauthorized firmware changes.
| Advantech EKI-1242EIMS | V1.06.01 (firmware version identified in the advisory; no other version ranges were provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.
- Weakness
- CWE-345
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.