Advantech EKI-1242EIMS v1.06.01 Remote AuthBypass in edgserver (TCP 5058)
CVE-2026-73173 Published on September 16, 2026
Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.
Vulnerability Analysis
CVE-2026-73173 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Affected Versions
Advantech EKI-1242IEIMS:- Before and including 1.06.01 is affected.
- Before and including 1.06.01 is affected.