← All Advisories

Advantech EKI-1242EIMS edgserver on TCP Port 5058 Requires No Authentication, Allowing Remote Attackers to Reconfigure the Network, Reboot, Reset, or Replace Firmware

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-73173

Key Details

CVECVE-2026-73173
CVSS Score / Version8.8 (High) / CVSS v4.0
Updated2026-09-23
Classified asCWE-306 (Missing Authentication for Critical Function)

What to Know

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73173
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73173