Executive brief
Advantech EKI-1242IEIMS is a network management device used in industrial and enterprise environments. An authenticated attacker can upload a malicious backup file through the web interface to overwrite critical system files, potentially compromising device integrity, availability, and confidentiality of operational data.
Technical details
This vulnerability is a CWE-73: External Control of File Name or Path flaw in the backup-restore workflow. An authenticated attacker can craft a backup archive with path traversal sequences to overwrite arbitrary files on the device filesystem when the archive is extracted during restoration. The attack requires network access to the web management interface and valid credentials, but no user interaction is needed beyond uploading the malicious file. Successful exploitation allows complete file system manipulation, potentially leading to privilege escalation, code execution, or denial of service. A patch is available: firmware version 2.00.01 or later resolves the issue.
Affected products
- Advantech EKI-1242IEIMS V1.06.01
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed
- 2026-09-04: patched: Firmware version 2.00.01 available