Description
Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Device Compromise
Action: Update Firmware
AI Analysis

Impact

The firmware upgrade mechanism of the Advantech EKI-1242EIMS accepts firmware images over the authenticated web management interface without any cryptographic signature or certificate verification. This deficiency, identified as CWE‑345, allows an administrator authenticated on the device to install arbitrary modified firmware. The result is a persistent, full platform compromise that could enable arbitrary code execution and long‑term control of the device.

Affected Systems

The vulnerability affects Advantech EKI-1242EIMS and EKI-1242IEIMS running firmware version V1.06.01. The affected devices are accessed through a web management interface that does not enforce cryptographic validation of firmware images.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity risk, yet the EPSS score of less than 1% shows the likelihood of public exploitation is currently low. The vulnerability is not listed in CISA KEV. A qualified attacker who has authenticated as an administrator can trivially upload and apply a malicious firmware payload, achieving full device takeover. The attack requires remote access to the local management interface and valid administrator credentials; no further prerequisites are documented.

Generated by OpenCVE AI on September 18, 2026 at 02:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Replace the current firmware with a patched version that includes cryptographic signature or certificate verification on firmware upgrades.
  • Restrict web management interface access to a limited, trusted set of IP addresses or VLANs to reduce the attack surface.
  • Disable or monitor any firmware upgrade pathways that bypass signature checks, and audit deployed firmware for authenticity.

Generated by OpenCVE AI on September 18, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Insufficient Firmware Image Verification Enables Arbitrary Firmware Installation on Advantech EKI-1242EIMS

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.
Weaknesses CWE-345
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:59:04.930Z

Reserved: 2026-08-11T09:36:40.350Z

Link: CVE-2026-73177

cve-icon Vulnrichment

Updated: 2026-09-17T18:58:58.767Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:08.133

Modified: 2026-09-17T19:16:56.263

Link: CVE-2026-73177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity