CSRF Vulnerability in Advantech EKI-1242IEIMS Web Interface
CVE-2026-19535

8.6HIGH

Key Information:

Vendor

Advantech

Vendor
CVE Published:
16 September 2026

What is CVE-2026-19535?

A critical weakness has been discovered in the LuCI administrative web interface of Advantech's EKI-1242IEIMS, which allows an unauthenticated remote attacker to send unauthorized state-changing requests on behalf of logged-in administrators. This vulnerability paves the way for attackers to gain unauthorized access to sensitive management functions, posing significant risks to the integrity and security of network configurations.

Affected Version(s)

EKI-1242EIMS 0 <= 1.06.01

EKI-1242IEIMS 0 <= 1.06.01

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simone Bossi at Nozomi Networks
.