← All Advisories

Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-73172

Key Details

CVECVE-2026-73172
CVSS Score / Version9.3 (Critical) / CVSS v4.0
Updated2026-09-23
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73172
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73172