Junglewise Threat Intelligence

CVE-2026-73169: Advantech EKI-1242EIMS stored cross-site scripting in Modbus interface

CVE-2026-73169 · Severity: info · CVSS 6.3 · Published 2026-09-16

Executive brief

Advantech EKI-1242EIMS is an industrial Ethernet gateway used in operational technology networks to manage Modbus connections. A stored cross-site scripting (XSS) vulnerability in its web-based management interface allows an authenticated administrator to inject malicious scripts that will execute in the browsers of other administrators accessing the Modbus transaction management page, potentially leading to credential theft, account compromise, or lateral movement within the industrial network.

Technical details

This is a CWE-79 stored cross-site scripting (XSS) vulnerability in the Modbus transaction management interface component of Advantech EKI-1242EIMS firmware version V1.06.01. The vulnerability allows an authenticated attacker with high privileges to inject malicious script content that persists in the application and executes in the browser of any administrator who subsequently opens the affected management page. Attack preconditions include valid administrative authentication and user interaction (victim must open the affected page). The vulnerability was patched in firmware version 2.00.01 as per the vendor's security advisory.

Affected products

  • Advantech EKI-1242EIMS V1.06.01

Timeline

  • 2026-09-16: disclosed: CVE-2026-73169 published
  • 2026: patched: Firmware version 2.00.01 available

References

Related threats