OS Command Injection Vulnerability in Advantech EKI-1242IEIMS Web Management Interface
CVE-2026-73164
8.6HIGH
Key Information:
- Vendor
Advantech
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-73164?
A vulnerability has been identified in the web management interface of the Advantech EKI-1242IEIMS, which allows remote authenticated attackers to execute arbitrary operating system commands with root privileges. This is due to improper neutralization of special elements in request parameters, categorized under CWE-78. Such an exploit can lead to severe consequences, including unauthorized access and control over the affected systems.
Affected Version(s)
EKI-1242EIMS 0 <= 1.06.01
EKI-1242IEIMS 0 <= 1.06.01
