Description
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Published: 2026-09-16
Score: 8.6 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A remote authenticated attacker can influence the web management interface of Advantech EKI‑1242IEIMS firmware V1.06.01 to inject arbitrary operating‑system commands. The vulnerability arises from improper neutralization of special elements in user‑supplied request parameters, allowing the attacker to execute commands with root privileges. This flaw provides full control over the underlying operating system, enabling the attacker to modify, delete, or exfiltrate data and to establish persistent compromise.

Affected Systems

Advantech EKI‑1242EIMS and EKI‑1242IEIMS devices running firmware version V1.06.01 are affected. The impacted component is the web management interface.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of <1% suggests a low exploitation probability at present. The vulnerability is not listed in CISA KEV. Because exploitation requires remote authentication, an attacker must first obtain valid login credentials to the web interface. Once authenticated, the attacker can construct a request with malicious parameters, triggering the OS command injection that executes as root.

Generated by OpenCVE AI on September 18, 2026 at 02:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Advantech that fixes the command‑injection flaw.
  • Restrict access to the web management interface by limiting it to trusted networks or by placing it behind an access‑control firewall, and use strong, unique credentials for authentication.
  • Enable comprehensive logging for web requests and system commands, and monitor logs for suspicious activity to detect potential abuse.

Generated by OpenCVE AI on September 18, 2026 at 02:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Advantech EKI‑1242IEIMS Firmware 1.06.01 Remote OS Command Injection Allowing Root Execution

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:48:24.768Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73163

cve-icon Vulnrichment

Updated: 2026-09-17T18:48:14.862Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:04.373

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')