Executive brief
The Advantech EKI-1242EIMS industrial network switch accepts firmware updates through its web management interface without verifying that the firmware image is signed or authentic. An authenticated administrator can upload a modified firmware image to completely compromise the device, gaining persistent control and enabling lateral movement into the connected industrial network.
Technical details
This vulnerability is a CWE-345 (Insufficient Verification of Data Authenticity) flaw in the firmware upgrade mechanism. The device accepts firmware images through the authenticated web management interface without performing cryptographic signature verification or certificate-based validation. An authenticated administrator-level attacker can upload an arbitrary modified firmware image, achieving full persistent compromise of the platform. The vulnerability affects Advantech EKI-1242EIMS in firmware version V1.06.01; a patch is available in firmware version 2.00.01.
Affected products
- Advantech EKI-1242EIMS V1.06.01
Timeline
- 2026-09-16: disclosed: CVE-2026-73177 published
- 2026-09-16: patched: Firmware version 2.00.01 addresses the vulnerability