← All Advisories

Advantech EKI-1242IEIMS Web Interface OS Command Injection Grants Root Access to Authenticated Administrators

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-73163

Key Details

CVECVE-2026-73163
CVSS Score / Version8.6 (High) / CVSS v4.0
Updated2026-09-23
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73163
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73163