CVE-2026-73169
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page.
| CWE | CWE-79 |
| Vendor | advantech |
| Product | eki-1242ieims |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for advantech eki-1242ieims
Be the first to know when new unknown vulnerabilities affecting advantech eki-1242ieims are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Advantech / EKI-1242IEIMS
0 โค 1.06.01
Advantech / EKI-1242EIMS
0 โค 1.06.01
References
Credits
Simone Bossi at Nozomi Networks