Description
Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an instance of code injection, identified as CWE-94, in the Modbus CSV import workflow of the Advantech EKI-1242EIMS. An attacker who is able to authenticate remotely can create a crafted import file that contains arbitrary Lua code; when the file is processed, the device executes the code on its internal interpreter. The result is full remote code execution on the device, allowing the attacker to read, modify, or destroy data and potentially use the device as a foothold for further network compromise.

Affected Systems

Affected products are Advantech EKI-1242EIMS and its industrial variant EKI-1242IEIMS running firmware version V1.06.01. Only these firmware versions were reported to contain the vulnerability; newer firmware versions may not be affected.

Risk and Exploitability

The CVSS score of 8.6 classifies the vulnerability as High, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a remote authenticated session and the ability to upload a file via the Modbus CSV import interface, which may be exposed over the network. Therefore, while the potential impact is severe if a credentialed attacker obtains access, the likelihood of exploitation is low in the absence of that precondition.

Generated by OpenCVE AI on September 18, 2026 at 03:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to a version that fixes the Modbus CSV import code injection flaw.
  • If a recent firmware update is not yet available, disable or restrict the Modbus CSV import feature or block its exposure to untrusted networks.
  • Ensure that device authentication uses strong, multi‑factor credentials and limit the number of users with administrative rights.
  • Monitor import logs for abnormal activity and investigate any unexpected file uploads.

Generated by OpenCVE AI on September 18, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Lua Injection in Advantech Modbus CSV Import

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:52:30.289Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73170

cve-icon Vulnrichment

Updated: 2026-09-17T18:52:26.262Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:05.220

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')