CVE-2026-73176: OS Command Injection
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to reach the device's web management interface and authenticate to it. The vulnerability is therefore most relevant where that interface is exposed to untrusted or broadly accessible networks or where attacker-controlled users can obtain valid credentials.
What level of access can successful exploitation provide?
Successful exploitation allows execution of arbitrary operating-system commands as root. This can give an authenticated attacker full control of the affected device.
Which firmware version is identified as affected?
The reported affected firmware version is V1.06.01 for the Advantech EKI-1242IEIMS.