← All Advisories

Advantech EKI-1242IEIMS Web Management Endpoint Executes Attacker-Supplied OS Commands as Root When Request Parameters Are Not Sanitized

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-73165

Key Details

CVECVE-2026-73165
CVSS Score / Version8.6 (High) / CVSS v4.0
Updated2026-09-23
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73165
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73165