CVE-2026-73166: Code Injection
Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remotely authenticated to the device's web management interface. Exploitation does not require physical access based on the available information.
What is the impact after successful exploitation?
An authenticated remote attacker can execute arbitrary code on the device, including operating-system commands as root. This could give the attacker full control of the affected device.
Which firmware version is identified as affected?
The vulnerability is identified in Advantech EKI-1242IEIMS firmware version V1.06.01.