OS Command Injection Vulnerability in Advantech EKI-1242IEIMS
CVE-2026-73176

8.6HIGH

Key Information:

Vendor

Advantech

Vendor
CVE Published:
16 September 2026

What is CVE-2026-73176?

A vulnerability exists in the web management interface of Advantech EKI-1242IEIMS, allowing remote authenticated attackers to execute arbitrary OS commands with root privileges through specially crafted request parameters. This flaw stems from inadequate neutralization of special elements, categorized as CWE-78, which poses significant security risks. Organizations utilizing affected firmware must prioritize patching to mitigate potential exploitation.

Affected Version(s)

EKI-1242EIMS 0 <= 1.06.01

EKI-1242IEIMS 0 <= 1.06.01

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simone Bossi at Nozomi Networks
.