Executive brief
Advantech EKI-1242IEIMS is an industrial-grade network device with a web-based management interface. A vulnerability in this interface allows authenticated administrators or authorized users with high privileges to execute arbitrary operating system commands with root-level access, potentially enabling complete system compromise and lateral movement within industrial networks.
Technical details
This is an OS command injection vulnerability (CWE-78) in the web management interface that fails to properly sanitize or neutralize special characters in request parameters. An attacker with high-level authentication privileges can craft malicious request parameters to inject arbitrary OS commands, which are then executed by the system with root privileges. The vulnerability requires network access to the management interface and high-level user privileges (PR:H), but once authenticated, allows full command execution. Advantech released firmware version 2.00.01 as a patched version addressing this issue.
Affected products
- Advantech EKI-1242IEIMS V1.06.01
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Firmware version 2.00.01 available