Junglewise Threat Intelligence

CVE-2026-19535: Advantech EKI-1242 CSRF in LuCI administrative interface

CVE-2026-19535 · Severity: info · CVSS 8.6 · Published 2026-09-16

Executive brief

The Advantech EKI-1242 industrial network switch contains a cross-site request forgery vulnerability in its web-based management interface. An attacker can trick a logged-in administrator into unknowingly performing privileged actions such as changing network settings or disabling security features, compromising the integrity and availability of critical infrastructure networks.

Technical details

A cross-site request forgery (CWE-352) vulnerability exists in the LuCI administrative web interface of the Advantech EKI-1242IEIMS and EKI-1242EIMS switches running firmware version V1.06.01. An unauthenticated remote attacker can craft a malicious web page that, when visited by a logged-in administrator, triggers unauthorized state-changing requests (such as configuration modifications) without the administrator's knowledge or consent. No special privileges or user interaction beyond browsing a malicious site is required for the attack. The vulnerability is resolved in firmware version 2.00.01.

Affected products

  • Advantech EKI-1242IEIMS V1.06.01
  • Advantech EKI-1242EIMS V1.06.01

Timeline

  • 2026-09-16: disclosed
  • 2026-09-04: patched: Firmware version 2.00.01 resolves the vulnerability

References

Related threats