Authenticated Command Injection
CVE-2023-2574
8.8HIGH
What is CVE-2023-2574?
Advantech's EKI-1524, EKI-1522, and EKI-1521 series devices, running firmware version 1.21 or earlier, are susceptible to a command injection vulnerability. This flaw enables authenticated attackers to exploit the device name input field through specifically crafted POST requests, potentially compromising the integrity and functionality of the devices. Users are strongly advised to upgrade to the latest firmware as patches are available to rectify this security issue.
Affected Version(s)
EKI-1521 0 <= 1.21
EKI-1522 0 <= 1.21
EKI-1524 0 <= 1.21