Junglewise Threat Intelligence

CVE-2026-73167: Advantech EKI-1242IEIMS OS command injection in web management interface

CVE-2026-73167 · Severity: info · CVSS 8.6 · Published 2026-09-16

Executive brief

Advantech EKI-1242IEIMS is a networked industrial device with a web-based management console. A vulnerability in that console allows an authenticated attacker to execute arbitrary commands with root privileges, potentially gaining complete control of the device and any systems it manages or connects to.

Technical details

The vulnerability is an OS command injection (CWE-78) in the web management interface of Advantech EKI-1242IEIMS firmware V1.06.01. The issue stems from improper neutralization of special elements in request parameters, allowing a remote authenticated attacker to inject and execute arbitrary OS commands with root privileges. The attack requires valid authentication credentials and network access to the management interface; no user interaction is needed. An attacker can achieve full command execution as root. The vendor has released a patch in firmware version 2.00.01.

Affected products

  • Advantech EKI-1242IEIMS V1.06.01
  • Advantech EKI-1242EIMS V1.06.01

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Firmware version 2.00.01 available

References

Related threats