Impact
Nozomi Networks Labs identified a code injection vulnerability (CWE-94) in the web management interface of Advantech EKI-1242IEIMS. The flaw allows an attacker with valid credentials to feed arbitrary code to the device, enabling execution of OS commands as root. This results in complete compromise of confidentiality, integrity, and availability of the device and any network resources it controls.
Affected Systems
The vulnerability is present in Advantech EKI-1242EIMS and Advantech EKI-1242IEIMS devices running firmware V1.06.01. No other firmware revisions were mentioned as affected. The affected assets are typically industrial control devices often deployed in critical infrastructure and locked environments.
Risk and Exploitability
The reported CVSS score of 8.6 indicates a high severity impact. The EPSS score of less than 1% suggests that zero‑day exploitation is currently unlikely, and the vulnerability is not listed in CISA's KEV catalog. The issue requires remote authentication over the web interface to reach the code generation endpoint, meaning the attacker must first compromise user credentials. Nonetheless, the potential for full root control warrants prompt remediation. Monitoring of login attempts and suspicious activity is advisable while a patch is applied.
OpenCVE Enrichment