Executive brief
Advantech EKI-1242EIMS is an industrial IoT device used to monitor and control Modbus networks. An authenticated attacker can upload a specially crafted CSV file that executes arbitrary Lua code on the device, potentially compromising operational technology infrastructure and enabling device manipulation or data theft.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the Modbus CSV import functionality of Advantech EKI-1242EIMS firmware version V1.06.01. The device improperly validates or sanitizes CSV input when importing Modbus configurations, allowing an attacker to embed and execute arbitrary Lua code. The attack requires network access and valid authentication credentials. An authenticated remote attacker can leverage this to execute arbitrary Lua code with device-level privileges, potentially compromising the integrity and availability of the device and connected industrial systems. The vendor has released firmware version 2.00.01 that fixes this issue.
Affected products
- Advantech EKI-1242EIMS V1.06.01
- Advantech EKI-1242IEIMS V1.06.01
Timeline
- 2026-09-16: disclosed
- 2026-09-04: patched: Firmware version 2.00.01 released