CVE-2026-19535: CSRF
Published Sep 16, 2026
·Updated
Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.
Affected Software
1 affected component
Advantech LuCI administrative web interface (EKI-1242IEIMS)=V1.06.01
Event History
Sep 16, 2026
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to exploitation?
Deployments of the Advantech EKI-1242IEIMS using firmware V1.06.01 are affected when the LuCI administrative web interface is in use and an administrator is logged in.
2
What must an attacker do to exploit this issue?
The attacker can be remote and does not need to authenticate, but must cause a logged-in administrator's browser to send state-changing requests to the LuCI interface on the attacker's behalf.