← All Advisories

Advantech EKI-1242IEIMS LuCI admin interface CSRF allows unauthenticated attacker to trigger privileged management actions

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-19535

Key Details

CVECVE-2026-19535
CVSS Score / Version8.6 (High) / CVSS v4.0
Updated2026-09-23
Classified asCWE-352 (Cross-Site Request Forgery (CSRF))

What to Know

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-19535
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-19535