Missing Authentication Vulnerability in Advantech EKI-1242EIMS Management Protocol
CVE-2026-73173

8.8HIGH

Key Information:

Vendor

Advantech

Vendor
CVE Published:
16 September 2026

What is CVE-2026-73173?

A vulnerability exists in the edgserver management protocol of Advantech EKI-1242EIMS that allows an unauthenticated remote attacker to execute critical device-management functions. By sending specially crafted requests to TCP port 5058, an attacker can perform actions such as network reconfiguration, rebooting the device, resetting it, and even upgrading the firmware. This poses significant risks to network security, enabling unauthorized control over the affected devices.

Affected Version(s)

EKI-1242EIMS 0 <= 1.06.01

EKI-1242IEIMS 0 <= 1.06.01

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simone Bossi at Nozomi Networks
.