CVE-2026-73177
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.
| CWE | CWE-345 |
| Vendor | advantech |
| Product | eki-1242ieims |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for advantech eki-1242ieims
Be the first to know when new unknown vulnerabilities affecting advantech eki-1242ieims are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Advantech / EKI-1242IEIMS
0 โค 1.06.01
Advantech / EKI-1242EIMS
0 โค 1.06.01
References
Credits
Simone Bossi at Nozomi Networks