Description
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: 2.2% Low
KEV: No
Impact: Remote command execution as root
Action: Immediate Patch
AI Analysis

Impact

An OS command injection flaw in the edgserver management service of Advantech EKI-1242 firmware enables an attacker to send specially crafted messages to TCP port 5058. The vulnerability, classified as CWE‑78, permits remote unauthenticated users to execute arbitrary operating‑system commands with root privileges, effectively granting complete control over the device. The impact is a full compromise of the affected system, including confidentiality, integrity, and availability losses.

Affected Systems

The flaw exists in Advantech EKI-1242EIMS and Advantech EKI-1242IEIMS devices running firmware version V1.06.01. Only these specific product releases are known to be affected; other firmware versions or models have not been reported as vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, and the EPSS score of 2% suggests a moderate likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw over the network by targeting port 5058 without authentication, making it highly attractive for remote attack campaigns.

Generated by OpenCVE AI on September 18, 2026 at 02:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the firmware to the latest version available from Advantech’s official release or apply the patch detailed in the Security Advisory PDF
  • If an upgrade is not immediately possible, block or restrict access to TCP port 5058 using a firewall or network segmentation to limit exposure to trusted hosts
  • Regularly monitor device logs for anomalous command execution or unexpected outbound connections, and alert administrators to suspicious activity

Generated by OpenCVE AI on September 18, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote OS Command Injection Allowing Root Execution on Advantech EKI-1242 Firmware

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:54:00.909Z

Reserved: 2026-08-11T09:36:13.097Z

Link: CVE-2026-73172

cve-icon Vulnrichment

Updated: 2026-09-17T18:53:57.546Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:05.600

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')