Description
Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Device Management
Action: Patch Now
AI Analysis

Impact

A missing authentication flaw in the edgserver management protocol of Advantech EKI-1242EIMS firmware V1.06.01 allows an attacker who is not authenticated to send crafted requests to TCP port 5058. The flaw enables the attacker to invoke critical device‑management functions such as network reconfiguration, reboot, reset, and firmware upgrade, effectively granting full control over the device’s operation.

Affected Systems

The affected devices are Advantech EKI-1242EIMS and EKI-1242IEIMS running firmware version V1.06.01.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity risk, while the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely without authentication by sending crafted packets to TCP port 5058, making the risk significant despite the low exploitation probability.

Generated by OpenCVE AI on September 18, 2026 at 03:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to a version that includes the authentication fix for the edgserver management protocol.
  • Restrict or block external access to TCP port 5058 using firewall or network segmentation rules.
  • Enable logging for management‑protocol traffic to detect unauthorized activity.

Generated by OpenCVE AI on September 18, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Management Control in Advantech EKI-1242 Firmware via TCP 5058

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:56:14.113Z

Reserved: 2026-08-11T09:36:40.350Z

Link: CVE-2026-73173

cve-icon Vulnrichment

Updated: 2026-09-17T18:56:10.327Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:05.733

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function