Description
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Published: 2026-09-16
Score: 8.6 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a classic command injection flaw (CWE‑78) in the web management interface of Advantech EKI‑1242EIMS and EKI‑1242IEIMS. An attacker who can authenticate to the device’s web interface can craft request parameters that, because they are not properly neutralized, are executed directly by the underlying operating system with root privileges. The flaw would allow arbitrary command execution and therefore compromise confidentiality, integrity, and availability of the device.

Affected Systems

The flaw affects the Advantech EKI‑1242EIMS and EKI‑1242IEIMS devices running firmware version V1.06.01. No other firmware revisions are reported to be susceptible.

Risk and Exploitability

The CVSS score of 8.6 designates this flaw as high severity. The EPSS score is below 1 %, meaning at present exploitation is considered unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the attack only requires valid credentials and a crafted request directed at the web interface, so an attacker who has gained a user account or compromised the network segment that can reach the device could actually exploit the flaw.

Generated by OpenCVE AI on September 18, 2026 at 03:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the firmware of the Advantech EKI‑1242EIMS and EKI‑1242IEIMS devices to the latest version as supplied in the official Advantech security advisory.
  • Restrict external access to the web management interface, limiting it to trusted networks or blocking it entirely until the patch is applied.
  • Enable multi‑factor authentication for the web interface or, if the interface is not needed, disable or remove it to reduce the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 03:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Advantech EKI-1242IEIMS Web Interface Allows Remote Root Execution

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:49:23.380Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73165

cve-icon Vulnrichment

Updated: 2026-09-17T18:49:18.015Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:04.693

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')