CVE-2026-73177
Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification.
An authenticated administrator-level attacker may install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.
September 16, 2026
This issue affects: Advantech EKI-1242IEIMS and EKI-1242EIMS in firmware version V1.06.01.
CVE-2026-73177
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
8.6
Update to firmware version 2.00.01.
Simone Bossi at Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more