Advantech EKI-1242EIMS Cleartext Leak via edgserver (CWE-319) V1.06.01
CVE-2026-73174 Published on September 16, 2026
Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.
Vulnerability Analysis
Weakness Type
Cleartext Transmission of Sensitive Information
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. Many communication channels can be "sniffed" by attackers during data transmission. For example, network traffic can often be sniffed by any attacker who has access to a network interface. This significantly lowers the difficulty of exploitation by attackers.
Affected Versions
Advantech EKI-1242IEIMS:- Before and including 1.06.01 is affected.
- Before and including 1.06.01 is affected.