Description
Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Nozomi Networks Labs identified a code injection vulnerability (CWE-94) in the web management interface of Advantech EKI-1242IEIMS. The flaw allows an attacker with valid credentials to feed arbitrary code to the device, enabling execution of OS commands as root. This results in complete compromise of confidentiality, integrity, and availability of the device and any network resources it controls.

Affected Systems

The vulnerability is present in Advantech EKI-1242EIMS and Advantech EKI-1242IEIMS devices running firmware V1.06.01. No other firmware revisions were mentioned as affected. The affected assets are typically industrial control devices often deployed in critical infrastructure and locked environments.

Risk and Exploitability

The reported CVSS score of 8.6 indicates a high severity impact. The EPSS score of less than 1% suggests that zero‑day exploitation is currently unlikely, and the vulnerability is not listed in CISA's KEV catalog. The issue requires remote authentication over the web interface to reach the code generation endpoint, meaning the attacker must first compromise user credentials. Nonetheless, the potential for full root control warrants prompt remediation. Monitoring of login attempts and suspicious activity is advisable while a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 02:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade from Advantech that fixes the code injection issue.
  • If an immediate firmware update is not possible, block the web management interface from all but trusted management IPs using firewall rules and enable network segmentation.
  • Enforce robust authentication policies: disable default accounts, enforce strong passwords or certificate‑based auth, and enable account lockout after repeated failures.
  • Keep the device polling logs to an external SIEM and configure alerts for anomalous command execution or unexpected configuration changes.

Generated by OpenCVE AI on September 18, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote Code Injection Vulnerability in Advantech EKI-1242IEIMS Firmware V1.06.01

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T19:11:05.990Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73166

cve-icon Vulnrichment

Updated: 2026-09-17T19:11:00.355Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:04.823

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')