Description
Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting in admin interface
Action: Patch Immediately
AI Analysis

Impact

A stored cross‑site scripting flaw exists in the Modbus transaction management interface of Advantech EKI‑1242EIMS firmware V1.06.01. An attacker who can authenticate to the interface can embed malicious script; when an administrator visits the page the script runs in their browser.

Affected Systems

Advantech EKI‑1242EIMS units running firmware version V1.06.01. The CNA also lists the EKI‑1242IEIMS product as affected, but the CVE description only specifies the firmware version for EKI‑1242EIMS. No other firmware or product versions are noted as affected.

Risk and Exploitability

The CVSS score of 6.3 classifies the vulnerability as moderate. The EPSS score of less than 1 % indicates a very low likelihood of exploitation, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires a remote authenticated attacker, meaning the attacker must first obtain valid credentials or compromise a user account to use the flaw. The impact is limited to browser sessions of administrators who access the affected management page.

Generated by OpenCVE AI on September 18, 2026 at 04:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware release for Advantech EKI‑1242EIMS that addresses the XSS flaw, as described in the vendor’s security advisory PDF.
  • Restrict access to the Modbus transaction management interface to trusted internal hosts by configuring appropriate firewall rules or network segmentation.
  • If the system allows it, disable or remove web‑based script storage features until the patch can be applied.
  • Implement strong password policies and enable multi‑factor authentication for all user accounts to reduce the chance of an attacker obtaining authenticated access.

Generated by OpenCVE AI on September 18, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:51:45.518Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73169

cve-icon Vulnrichment

Updated: 2026-09-17T18:51:39.051Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:05.077

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')