Description
Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privileged Function Abuse via CSRF
Action: Patch
AI Analysis

Impact

Advantech’s EKI-1242IEIMS firmware contains a Cross‑Site Request Forgery flaw in its LuCI administrative web interface. An attacker who can cause a logged‑in administrator to unknowingly visit a crafted URL can send state‑changing requests on the administrator’s behalf, enabling the attacker to perform privileged management functions without authentication.

Affected Systems

Advantech EKI-1242EIMS and EKI-1242IEIMS running firmware version V1.06.01 are affected. The vulnerability is limited to the LuCI web interface of these devices.

Risk and Exploitability

The CVSS score of 8.6 indicates a high risk of unauthorized privilege escalation. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated web‑based CSRF attack where an adversary tricks a legitimate administrator into submitting a maliciously crafted request to the device’s admin interface.

Generated by OpenCVE AI on September 18, 2026 at 02:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device to a firmware version that removes the CSRF vulnerability or await an official patch from Advantech.
  • If an update is not immediately available, add CSRF protection to the LuCI interface by requiring anti‑CSRF tokens or additional user confirmation for all state‑changing requests.
  • Restrict external access to the LuCI administrative interface using firewalls or VPNs so that only trusted, authenticated personnel can reach it.

Generated by OpenCVE AI on September 18, 2026 at 02:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in LuCI Admin Interface of Advantech EKI‑1242IEIMS

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:47:44.061Z

Reserved: 2026-08-11T09:36:52.957Z

Link: CVE-2026-19535

cve-icon Vulnrichment

Updated: 2026-09-17T18:47:30.387Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:17:20.510

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-19535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)