Impact
A remote authenticated attacker can influence the web management interface of Advantech EKI‑1242IEIMS firmware V1.06.01 to inject arbitrary operating‑system commands. The vulnerability arises from improper neutralization of special elements in user‑supplied request parameters, allowing the attacker to execute commands with root privileges. This flaw provides full control over the underlying operating system, enabling the attacker to modify, delete, or exfiltrate data and to establish persistent compromise.
Affected Systems
Advantech EKI‑1242EIMS and EKI‑1242IEIMS devices running firmware version V1.06.01 are affected. The impacted component is the web management interface.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of <1% suggests a low exploitation probability at present. The vulnerability is not listed in CISA KEV. Because exploitation requires remote authentication, an attacker must first obtain valid login credentials to the web interface. Once authenticated, the attacker can construct a request with malicious parameters, triggering the OS command injection that executes as root.
OpenCVE Enrichment