Impact
The vulnerability is an OS Command Injection flaw that allows a remote authenticated attacker to submit crafted request parameters to the web management interface of Advantech EKI‑1242IEIMS. The flaw results in the execution of arbitrary OS commands with root privileges. This gives an attacker full control over the device, enabling installation of malware, theft of data, or disruption of its services.
Affected Systems
Advantech EKI‑1242EIMS and Advantech EKI‑1242IEIMS models running firmware version V1.06.01 are affected. No other firmware versions or models are listed as impacted.
Risk and Exploitability
The flaw carries a high severity CVSS score of 8.6 and an EPSS score of less than 1 %, indicating a low but non‑zero chance of exploitation in the current environment. It is not listed in the CISA KEV catalog, suggesting that no publicly known exploits are active. The attacker must possess valid credentials to the web management interface but can then elevate to root and execute arbitrary commands.
OpenCVE Enrichment