Impact
This vulnerability is a classic command injection flaw (CWE‑78) in the web management interface of Advantech EKI‑1242EIMS and EKI‑1242IEIMS. An attacker who can authenticate to the device’s web interface can craft request parameters that, because they are not properly neutralized, are executed directly by the underlying operating system with root privileges. The flaw would allow arbitrary command execution and therefore compromise confidentiality, integrity, and availability of the device.
Affected Systems
The flaw affects the Advantech EKI‑1242EIMS and EKI‑1242IEIMS devices running firmware version V1.06.01. No other firmware revisions are reported to be susceptible.
Risk and Exploitability
The CVSS score of 8.6 designates this flaw as high severity. The EPSS score is below 1 %, meaning at present exploitation is considered unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the attack only requires valid credentials and a crafted request directed at the web interface, so an attacker who has gained a user account or compromised the network segment that can reach the device could actually exploit the flaw.
OpenCVE Enrichment