CVE-2026-73173
Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol.
A remote unauthenticated attacker may invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058
September 16, 2026
This issue affects: Advantech EKI-1242IEIMS and EKI-1242EIMS in firmware version V1.06.01.
CVE-2026-73173
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
8.8
Update to firmware version 2.00.01.
Simone Bossi at Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more