Description
Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Overwrite
Action: Immediate Patch
AI Analysis

Impact

Nozomi Networks Labs disclosed a flaw identified as CWE‑73, External Control of File Name or Path, in the backup‑restore workflow of Advantech EKI‑1242EIMS firmware version V1.06.01. The vulnerability allows a remote authenticated attacker who can access the device’s web‑based management interface to upload a specially crafted backup archive that triggers the system to overwrite arbitrary files on the device file system. By selecting any target path, an attacker can modify configuration files, replace executables, or delete critical data, thereby compromising confidentiality, integrity, and availability of the device’s operation.

Affected Systems

The affected products are Advantech EKI‑1242EIMS and Advantech EKI‑1242IEIMS. Only firmware version V1.06.01 is confirmed to be vulnerable; newer versions are not publicly identified as affected.

Risk and Exploitability

The vulnerability has a CVSS score of 8.6, classifying it as high severity, but the EPSS score is indicated as less than 1 %, suggesting a low probability of exploitation at this time. The flaw is listed as not in CISA’s KEV catalog. The attack requires valid authentication credentials to the device’s web management interface; an attacker can exploit the flaw remotely by uploading a malicious backup archive once authenticated. The exposed ability to overwrite files provides a path to further compromise the device if an attacker can execute arbitrary code or persist malicious state.

Generated by OpenCVE AI on September 18, 2026 at 02:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued firmware update that fixes the file‑path validation issue in the backup‑restore process.
  • Limit web‑management interface exposure to trusted networks and enforce strict authentication so only authorized personnel can upload backups.
  • Validate or verify backup archives before processing—e.g., enforce checksums or digital signatures—to prevent delivery of malicious content when a patch is pending.

Generated by OpenCVE AI on September 18, 2026 at 02:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote File Overwrite via Crafted Backup in Advantech EKI-1242EIMS

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:52:54.931Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73171

cve-icon Vulnrichment

Updated: 2026-09-17T18:52:51.379Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:05.350

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-73

    External Control of File Name or Path