Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-73172: Advantech EKI-1242EIMS allows remote attacker to run commands as root
CVE-2026-73172 · published 24 days ago
Summary
The management service in Advantech EKI-1242EIMS firmware version V1.06.01 can be tricked into executing any system command it receives on TCP port 5058. This means an unauthenticated outsider could take full control of the device with administrative privileges. Update to a patched firmware version or block the vulnerable port until a fix is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| advantech | eki-1242ieims | <= 1.06.01 |
| advantech | eki-1242eims | <= 1.06.01 |
Original advisory text
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech E...
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-78OS Command Injection
Timeline
Published16 Sep 2026
Updated7 Oct 2026
First seen16 Sep 2026
Track software like this
Free during beta