Impact
Nozomi Networks Labs disclosed a flaw identified as CWE‑73, External Control of File Name or Path, in the backup‑restore workflow of Advantech EKI‑1242EIMS firmware version V1.06.01. The vulnerability allows a remote authenticated attacker who can access the device’s web‑based management interface to upload a specially crafted backup archive that triggers the system to overwrite arbitrary files on the device file system. By selecting any target path, an attacker can modify configuration files, replace executables, or delete critical data, thereby compromising confidentiality, integrity, and availability of the device’s operation.
Affected Systems
The affected products are Advantech EKI‑1242EIMS and Advantech EKI‑1242IEIMS. Only firmware version V1.06.01 is confirmed to be vulnerable; newer versions are not publicly identified as affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.6, classifying it as high severity, but the EPSS score is indicated as less than 1 %, suggesting a low probability of exploitation at this time. The flaw is listed as not in CISA’s KEV catalog. The attack requires valid authentication credentials to the device’s web management interface; an attacker can exploit the flaw remotely by uploading a malicious backup archive once authenticated. The exposed ability to overwrite files provides a path to further compromise the device if an attacker can execute arbitrary code or persist malicious state.
OpenCVE Enrichment