Executive brief
Advantech EKI-1242EIMS is an industrial Ethernet gateway used in operational technology networks to manage Modbus connections. A stored cross-site scripting (XSS) vulnerability in its web-based management interface allows an authenticated administrator to inject malicious scripts that will execute in the browsers of other administrators accessing the Modbus transaction management page, potentially leading to credential theft, account compromise, or lateral movement within the industrial network.
Technical details
This is a CWE-79 stored cross-site scripting (XSS) vulnerability in the Modbus transaction management interface component of Advantech EKI-1242EIMS firmware version V1.06.01. The vulnerability allows an authenticated attacker with high privileges to inject malicious script content that persists in the application and executes in the browser of any administrator who subsequently opens the affected management page. Attack preconditions include valid administrative authentication and user interaction (victim must open the affected page). The vulnerability was patched in firmware version 2.00.01 as per the vendor's security advisory.
Affected products
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed: CVE-2026-73169 published
- 2026: patched: Firmware version 2.00.01 available