OS Command Injection Vulnerability in Advantech EKI-1242EIMS Management Service
CVE-2026-73172
9.3CRITICAL
Key Information:
- Vendor
Advantech
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-73172?
An OS Command Injection vulnerability exists in the management service of the Advantech EKI-1242EIMS in firmware version V1.06.01. This flaw allows an unauthenticated remote attacker to exploit specially crafted requests sent to TCP port 5058, enabling them to execute arbitrary operating system commands with root privileges. This vulnerability poses a significant risk, as it can lead to unauthorized access and control over affected systems.
Affected Version(s)
EKI-1242EIMS 0 <= 1.06.01
EKI-1242IEIMS 0 <= 1.06.01
