CVE-2026-73163: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech EKI-1242IEIMSto a version that resolves this vulnerability.Fixed in V1.06.01
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
A remote attacker who is authenticated to the web management interface can exploit it. The provided information does not indicate that unauthenticated access is sufficient.
What level of access could successful exploitation provide?
Successful exploitation allows execution of arbitrary operating-system commands as root, giving the attacker full privileged control of the affected device.
Which firmware version is identified as affected?
The vulnerability is identified in firmware version V1.06.01 for the Advantech EKI-1242IEIMS.