Executive brief
The Advantech EKI-1242 industrial network switch contains a cross-site request forgery vulnerability in its web-based management interface. An attacker can trick a logged-in administrator into unknowingly performing privileged actions such as changing network settings or disabling security features, compromising the integrity and availability of critical infrastructure networks.
Technical details
A cross-site request forgery (CWE-352) vulnerability exists in the LuCI administrative web interface of the Advantech EKI-1242IEIMS and EKI-1242EIMS switches running firmware version V1.06.01. An unauthenticated remote attacker can craft a malicious web page that, when visited by a logged-in administrator, triggers unauthorized state-changing requests (such as configuration modifications) without the administrator's knowledge or consent. No special privileges or user interaction beyond browsing a malicious site is required for the attack. The vulnerability is resolved in firmware version 2.00.01.
Affected products
- Advantech EKI-1242IEIMS V1.06.01
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed
- 2026-09-04: patched: Firmware version 2.00.01 resolves the vulnerability