Executive brief
Advantech EKI-1242IEIMS is an industrial Ethernet device used in networked automation and control systems. A remote authenticated attacker can inject and execute arbitrary operating system commands with root-level privileges through the device's web management interface, allowing complete system compromise and potential disruption of critical industrial operations.
Technical details
This is a CWE-78 OS command injection vulnerability in the web management interface of Advantech EKI-1242IEIMS and EKI-1242EIMS running firmware V1.06.01. The vulnerability exists in request parameter handling, where insufficient input validation allows an attacker to craft malicious requests containing shell metacharacters that are executed as root. Exploitation requires authentication to the web management interface but no user interaction. A successful exploit grants full remote command execution with root privileges. The vulnerability is fixed in firmware version 2.00.01 and later.
Affected products
- Advantech EKI-1242IEIMS V1.06.01
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed: CVE-2026-73176 published by Nozomi Networks Labs