Description
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Published: 2026-09-16
Score: 8.6 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Code Execution
Action: Patch ASAP
AI Analysis

Impact

Nozomi Networks Labs discovered that the web management interface of Advantech EKI-1242IEIMS contains an OS Command Injection flaw. The vulnerability permits an attacker who can authenticate to the interface to supply crafted request parameters that are passed to the operating system without proper sanitization. An attacker can thus execute arbitrary commands with root privileges, compromising the entire device.

Affected Systems

The issue affects Advantech EKI-1242EIMS and EKI-1242IEIMS devices running firmware version V1.06.01. The vulnerability is present only in this firmware release; no other versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity. The EPSS score is less than 1 %, suggesting low current exploitation activity, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves sending crafted request parameters to the web management interface of the device. The flaw requires authenticated access to the interface; an attacker who has valid credentials can send crafted request parameters that cause the device to execute arbitrary OS commands as root. Successful exploitation would give the attacker root privilege, permitting full control of the device and any services it hosts.

Generated by OpenCVE AI on September 18, 2026 at 04:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check with Advantech for a firmware update that addresses the OS command injection flaw and deploy it.
  • Restrict the web management interface to trusted internal networks only, and block external access via firewall rules.
  • Enforce strong, unique credentials on the web interface and implement multi‑factor authentication if available.

Generated by OpenCVE AI on September 18, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Advantech EKI-1242 Firmware

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:51:15.648Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73167

cve-icon Vulnrichment

Updated: 2026-09-17T18:51:10.439Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:04.950

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')