CVE-2026-73166

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Sep 2026, 13:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 13:18

Updated : 2026-09-16 19:41


NVD link : CVE-2026-73166

Mitre link : CVE-2026-73166

CVE.ORG link : CVE-2026-73166


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')