CVE-2026-73170: Code Injection
Published Sep 16, 2026
·Updated
Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.
Affected Software
1 affected component
Advantech EKI-1242EIMS=V1.06.01
Event History
Sep 16, 2026
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must be remotely authenticated and able to submit a crafted file through the Modbus CSV import workflow.
2
Which device and firmware version are identified as affected?
The issue is identified in Advantech EKI-1242EIMS firmware version V1.06.01.
3
What is the impact of successful exploitation?
A successful attacker can execute arbitrary Lua code on the affected device.