Executive brief
Advantech's EKI-1242IEIMS is an industrial network management device used to monitor and control critical infrastructure. A code injection vulnerability in its web management interface allows authenticated attackers to execute arbitrary commands as root, potentially compromising the entire device and any systems it manages.
Technical details
The vulnerability is a CWE-94 code injection flaw in the web management interface of Advantech EKI-1242IEIMS firmware version V1.06.01. An authenticated remote attacker can inject arbitrary code that executes with root privileges on the device, including OS commands. The attack requires valid credentials but no user interaction. Nozomi Networks Labs discovered and reported the issue; a firmware update to version 2.00.01 is available to address the vulnerability.
Affected products
- Advantech EKI-1242IEIMS V1.06.01
Timeline
- 2026-09-16: disclosed
- 2026-09-04: patched: Firmware version 2.00.01 available