File Name Control Vulnerability in Advantech EKI-1242EIMS
CVE-2026-73171

8.6HIGH

Key Information:

Vendor

Advantech

Vendor
CVE Published:
16 September 2026

What is CVE-2026-73171?

A vulnerability has been identified in the backup-restore workflow of Advantech EKI-1242EIMS that permits a remote authenticated attacker to potentially manipulate the filesystem. By uploading a specially crafted backup archive through the web management interface, the attacker could overwrite arbitrary files, which may lead to unauthorized access or compromise of the device’s functionality. This highlights the importance of securing access and validating file uploads to prevent exploitation.

Affected Version(s)

EKI-1242EIMS 0 <= 1.06.01

EKI-1242IEIMS 0 <= 1.06.01

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simone Bossi at Nozomi Networks
.