CVE-2026-73174: Advantech EKI-1242EIMS vulnerability
Published Sep 16, 2026
·Updated
Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.
Affected Software
1 affected component
Advantech EKI-1242EIMS=V1.06.01
Event History
Sep 16, 2026
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can observe the affected traffic?
A network-adjacent passive observer who can monitor the edgserver management protocol traffic can intercept it. The issue concerns management traffic exposed in cleartext.
2
What information could be recovered from intercepted traffic?
An observer can recover sensitive device identity and network metadata transmitted by the management protocol.
3
Which firmware version is identified as affected?
The reported affected version is firmware V1.06.01 for the Advantech EKI-1242EIMS.