Impact
A missing authentication flaw in the edgserver management protocol of Advantech EKI-1242EIMS firmware V1.06.01 allows an attacker who is not authenticated to send crafted requests to TCP port 5058. The flaw enables the attacker to invoke critical device‑management functions such as network reconfiguration, reboot, reset, and firmware upgrade, effectively granting full control over the device’s operation.
Affected Systems
The affected devices are Advantech EKI-1242EIMS and EKI-1242IEIMS running firmware version V1.06.01.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity risk, while the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely without authentication by sending crafted packets to TCP port 5058, making the risk significant despite the low exploitation probability.
OpenCVE Enrichment