CVE-2026-73173
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.
| CWE | CWE-306 |
| Vendor | advantech |
| Product | eki-1242ieims |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for advantech eki-1242ieims
Be the first to know when new unknown vulnerabilities affecting advantech eki-1242ieims are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Advantech / EKI-1242IEIMS
0 โค 1.06.01
Advantech / EKI-1242EIMS
0 โค 1.06.01
References
Credits
Simone Bossi at Nozomi Networks