CVE-2026-73172: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to remote exploitation?
Advantech EKI-1242EIMS devices running firmware V1.06.01 are exposed through the edgserver management service on TCP port 5058. The attack can be performed remotely without authentication.
What level of access can an attacker obtain?
A successful attacker can execute arbitrary operating-system commands as root, giving them the highest privilege level on the affected device.
What network condition is required for exploitation?
The attacker must be able to reach TCP port 5058 on the affected device and send crafted requests to the edgserver management service. No credentials are required.