Impact
Advantech’s EKI-1242IEIMS firmware contains a Cross‑Site Request Forgery flaw in its LuCI administrative web interface. An attacker who can cause a logged‑in administrator to unknowingly visit a crafted URL can send state‑changing requests on the administrator’s behalf, enabling the attacker to perform privileged management functions without authentication.
Affected Systems
Advantech EKI-1242EIMS and EKI-1242IEIMS running firmware version V1.06.01 are affected. The vulnerability is limited to the LuCI web interface of these devices.
Risk and Exploitability
The CVSS score of 8.6 indicates a high risk of unauthorized privilege escalation. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated web‑based CSRF attack where an adversary tricks a legitimate administrator into submitting a maliciously crafted request to the device’s admin interface.
OpenCVE Enrichment