Impact
The firmware upgrade mechanism of the Advantech EKI-1242EIMS accepts firmware images over the authenticated web management interface without any cryptographic signature or certificate verification. This deficiency, identified as CWE‑345, allows an administrator authenticated on the device to install arbitrary modified firmware. The result is a persistent, full platform compromise that could enable arbitrary code execution and long‑term control of the device.
Affected Systems
The vulnerability affects Advantech EKI-1242EIMS and EKI-1242IEIMS running firmware version V1.06.01. The affected devices are accessed through a web management interface that does not enforce cryptographic validation of firmware images.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity risk, yet the EPSS score of less than 1% shows the likelihood of public exploitation is currently low. The vulnerability is not listed in CISA KEV. A qualified attacker who has authenticated as an administrator can trivially upload and apply a malicious firmware payload, achieving full device takeover. The attack requires remote access to the local management interface and valid administrator credentials; no further prerequisites are documented.
OpenCVE Enrichment