OS Command Injection Vulnerability in Advantech EKI-1242IEIMS Firmware
CVE-2026-73167
8.6HIGH
Key Information:
- Vendor
Advantech
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-73167?
A security flaw in the web management interface of Advantech EKI-1242IEIMS allows authenticated attackers to execute arbitrary OS commands. This vulnerability, characterized as improper neutralization of special elements used in OS commands, can lead to unauthorized actions with root privileges when specific request parameters are crafted carefully. Users of the affected firmware version should take immediate action to secure their systems.
Affected Version(s)
EKI-1242EIMS 0 <= 1.06.01
EKI-1242IEIMS 0 <= 1.06.01
