Description
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Published: 2026-09-16
Score: 8.6 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS Command Injection flaw that allows a remote authenticated attacker to submit crafted request parameters to the web management interface of Advantech EKI‑1242IEIMS. The flaw results in the execution of arbitrary OS commands with root privileges. This gives an attacker full control over the device, enabling installation of malware, theft of data, or disruption of its services.

Affected Systems

Advantech EKI‑1242EIMS and Advantech EKI‑1242IEIMS models running firmware version V1.06.01 are affected. No other firmware versions or models are listed as impacted.

Risk and Exploitability

The flaw carries a high severity CVSS score of 8.6 and an EPSS score of less than 1 %, indicating a low but non‑zero chance of exploitation in the current environment. It is not listed in the CISA KEV catalog, suggesting that no publicly known exploits are active. The attacker must possess valid credentials to the web management interface but can then elevate to root and execute arbitrary commands.

Generated by OpenCVE AI on September 18, 2026 at 03:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Consult Advantech and apply any firmware update that removes this OS command injection flaw.
  • Restrict access to the web management interface by configuring firewalls or VPNs so that only authorized IP ranges can reach it.
  • If a patch is not yet available, disable or limit the exposed API endpoints or configuration pages that accept user input until the vulnerability is fixed.

Generated by OpenCVE AI on September 18, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection via Web Interface on Advantech EKI‑1242IEIMS

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:48:53.645Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73164

cve-icon Vulnrichment

Updated: 2026-09-17T18:48:46.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:04.543

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')