OS Command Injection Vulnerability in Advantech EKI-1242IEIMS
CVE-2026-73163
8.6HIGH
Key Information:
- Vendor
Advantech
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-73163?
A significant vulnerability exists in the web management interface of the Advantech EKI-1242IEIMS, specifically in firmware version V1.06.01, that permits a remote authenticated attacker to execute arbitrary operating system commands as root. This is made possible through improper neutralization of special elements in OS commands, allowing crafted request parameters to facilitate unauthorized command execution.
Affected Version(s)
EKI-1242EIMS 0 <= 1.06.01
EKI-1242IEIMS 0 <= 1.06.01
