Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Remote File Overwrite via Crafted Backup in Advantech EKI-1242EIMS |
Thu, 17 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech
Advantech eki-1242eims Advantech eki-1242ieims |
|
| Vendors & Products |
Advantech
Advantech eki-1242eims Advantech eki-1242ieims |
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface. | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2026-09-17T18:52:54.931Z
Reserved: 2026-08-11T09:36:13.097Z
Link: CVE-2026-73171
Updated: 2026-09-17T18:52:51.379Z
Status : Awaiting Analysis
Published: 2026-09-16T13:18:05.350
Modified: 2026-09-17T19:16:55.453
Link: CVE-2026-73171
No data.
OpenCVE Enrichment
Updated: 2026-09-18T03:00:09Z