Junglewise Threat Intelligence

CVE-2026-73173: Advantech EKI-1242IEIMS missing authentication in management protocol

CVE-2026-73173 · Severity: info · CVSS 8.8 · Published 2026-09-16

Executive brief

Advantech EKI-1242IEIMS and EKI-1242EIMS are industrial edge computing devices used to manage and control network infrastructure in critical environments. A remote attacker can bypass authentication on the management protocol and perform critical functions such as rebooting the device, reconfiguring its network settings, resetting it to factory state, or uploading new firmware—without any credentials or user interaction. This could lead to service disruption, unauthorized changes to network configuration, or deployment of malicious firmware.

Technical details

The vulnerability is a CWE-306 missing authentication flaw in the edgserver management protocol. The vulnerable component listens on TCP port 5058 and accepts crafted management requests without requiring authentication. A remote, unauthenticated attacker on the network can invoke critical device-management functions including network reconfiguration, reboot, reset, and firmware upgrade. No preconditions such as prior authentication or special privileges are required; the attack vector is network-based. Advantech has released firmware version 2.00.01 as a fix.

Affected products

  • Advantech EKI-1242IEIMS V1.06.01
  • Advantech EKI-1242EIMS V1.06.01

Timeline

  • 2026-09-16: disclosed

References

Related threats