CVE-2026-73170
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.
| CWE | CWE-94 |
| Vendor | advantech |
| Product | eki-1242ieims |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for advantech eki-1242ieims
Be the first to know when new unknown vulnerabilities affecting advantech eki-1242ieims are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Advantech / EKI-1242IEIMS
0 โค 1.06.01
Advantech / EKI-1242EIMS
0 โค 1.06.01
References
Credits
Simone Bossi at Nozomi Networks