Junglewise Threat Intelligence

CVE-2026-73164: Advantech EKI-1242IEIMS OS command injection in web management

CVE-2026-73164 · Severity: info · CVSS 8.6 · Published 2026-09-16

Executive brief

Advantech EKI-1242IEIMS is an industrial networking device with a web-based management interface. A remote authenticated attacker can execute arbitrary commands with root privileges by sending specially crafted requests to this interface, potentially compromising the entire device and any systems it controls.

Technical details

A CWE-78 OS command injection vulnerability exists in the web management interface of Advantech EKI-1242IEIMS due to improper neutralization of special elements in OS commands. The vulnerability allows a remote authenticated attacker to execute arbitrary OS commands with root privileges through crafted request parameters. Attack requires prior authentication and network access to the web management interface. The vulnerability affects firmware version V1.06.01 and has been patched in firmware version 2.00.01.

Affected products

  • Advantech EKI-1242IEIMS V1.06.01

Timeline

  • 2026-09-16: disclosed

References

Related threats