Junglewise Threat Intelligence

CVE-2026-73172: Advantech EKI-1242EIMS OS command injection in edgserver management

CVE-2026-73172 · Severity: info · CVSS 9.3 · Published 2026-09-16

Executive brief

The Advantech EKI-1242EIMS is an industrial network device used to manage and monitor critical infrastructure equipment. A remote attacker can execute arbitrary commands with root-level privileges on the device by sending crafted requests to its management service, potentially compromising network operations and providing a foothold for broader infrastructure attacks.

Technical details

A CWE-78 OS command injection vulnerability exists in the edgserver management service running on TCP port 5058 of the EKI-1242EIMS. The vulnerability stems from improper neutralization of special elements in OS commands, allowing unauthenticated remote attackers to inject arbitrary commands. No authentication is required, and the attack is network-reachable. Successful exploitation grants root-level command execution on the device. Advantech has released a patch in firmware version 2.00.01 to address this issue.

Affected products

  • Advantech EKI-1242EIMS V1.06.01

Timeline

  • 2026-09-16: disclosed

References

Related threats