Insufficient Data Verification in Advantech EKI-1242EIMS Firmware Upgrade Mechanism
CVE-2026-73177
8.6HIGH
Key Information:
- Vendor
Advantech
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-73177?
A vulnerability exists in the firmware upgrade process of Advantech EKI-1242EIMS, as identified by Nozomi Networks Labs. The issue arises from the device's inability to validate firmware images through cryptographic signatures or certificate checks when accessed via the authenticated web management interface. This oversight allows an authenticated administrator-tier attacker to upload and execute arbitrary modified firmware, potentially leading to a complete and persistent compromise of the device.
Affected Version(s)
EKI-1242EIMS 0 <= 1.06.01
EKI-1242IEIMS 0 <= 1.06.01
