Executive brief
Advantech EKI-1242 devices are industrial edge computing appliances used to manage and monitor network infrastructure in operational technology environments. A vulnerability in the management protocol allows a network-adjacent attacker to intercept and read sensitive device identity and network metadata in cleartext, potentially compromising network security and enabling further attacks on the infrastructure.
Technical details
This CWE-319 vulnerability exists in the edgserver management protocol of Advantech EKI-1242IEIMS and EKI-1242EIMS devices running firmware version V1.06.01. The management protocol transmits sensitive device identity and network metadata without encryption, allowing a network-adjacent passive observer to intercept and recover this information. No authentication or user interaction is required; an attacker only needs network proximity to the device. The vulnerability has been addressed in firmware version 2.00.01.
Affected products
- Advantech EKI-1242IEIMS V1.06.01
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed