CVE-2026-73171: Advantech EKI-1242EIMS vulnerability
Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be authenticated to the device's web management interface and able to upload a crafted backup archive.
Which deployments are known to be affected?
The issue is identified in Advantech EKI-1242EIMS firmware version V1.06.01. The provided information does not establish whether other firmware versions are affected.
What could successful exploitation allow?
A successful attacker can overwrite arbitrary files on the device filesystem through the backup-restore workflow.