Executive brief
The Advantech EKI-1242EIMS is an industrial network device used to manage and monitor critical infrastructure equipment. A remote attacker can execute arbitrary commands with root-level privileges on the device by sending crafted requests to its management service, potentially compromising network operations and providing a foothold for broader infrastructure attacks.
Technical details
A CWE-78 OS command injection vulnerability exists in the edgserver management service running on TCP port 5058 of the EKI-1242EIMS. The vulnerability stems from improper neutralization of special elements in OS commands, allowing unauthenticated remote attackers to inject arbitrary commands. No authentication is required, and the attack is network-reachable. Successful exploitation grants root-level command execution on the device. Advantech has released a patch in firmware version 2.00.01 to address this issue.
Affected products
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed