Impact
This vulnerability is an instance of code injection, identified as CWE-94, in the Modbus CSV import workflow of the Advantech EKI-1242EIMS. An attacker who is able to authenticate remotely can create a crafted import file that contains arbitrary Lua code; when the file is processed, the device executes the code on its internal interpreter. The result is full remote code execution on the device, allowing the attacker to read, modify, or destroy data and potentially use the device as a foothold for further network compromise.
Affected Systems
Affected products are Advantech EKI-1242EIMS and its industrial variant EKI-1242IEIMS running firmware version V1.06.01. Only these firmware versions were reported to contain the vulnerability; newer firmware versions may not be affected.
Risk and Exploitability
The CVSS score of 8.6 classifies the vulnerability as High, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a remote authenticated session and the ability to upload a file via the Modbus CSV import interface, which may be exposed over the network. Therefore, while the potential impact is severe if a credentialed attacker obtains access, the likelihood of exploitation is low in the absence of that precondition.
OpenCVE Enrichment