Description
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Published: 2026-09-16
Score: 8.6 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS Command Injection flaw (CWE-78) in the web management interface of Advantech EKI-1242EIMS and EKI-1242IEIMS. An authenticated attacker can send specially crafted request parameters that are directly passed to the operating system, allowing arbitrary commands to be executed with root privileges. This elevates the potential impact to full system compromise, including data theft, modification, or availability disruption.

Affected Systems

Advantech EKI-1242EIMS and EKI-1242IEIMS firmware version V1.06.01 are affected. The flaw exists in the web management interface accessed remotely over the network.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The flaw requires remote authenticated access, which means it can be mitigated by disabling remote management for untrusted networks. It is not listed in CISA's KEV catalog, so there are no publicly known exploits yet. The attack vector is inferred to be a web-based request to the management interface, with the attacker needing valid credentials but no privileged network access beyond availability of the interface.

Generated by OpenCVE AI on September 18, 2026 at 03:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the firmware update released by Advantech that addresses command injection in the web management interface.
  • Restrict network access to the management interface so it is only reachable from trusted internal segments or through a secure VPN.
  • Enforce the principle of least privilege on accounts that can access the web interface, and delete or disable any unused or unnecessary administrative users.

Generated by OpenCVE AI on September 18, 2026 at 03:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Advantech EKI-1242IEIMS Firmware v1.06.01 Allows Remote Authenticated Attacker to Execute Commands as Root

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:58:32.508Z

Reserved: 2026-08-11T09:36:40.350Z

Link: CVE-2026-73176

cve-icon Vulnrichment

Updated: 2026-09-17T18:58:28.301Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:06.163

Modified: 2026-09-23T10:10:00.673

Link: CVE-2026-73176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')