Advantech EKI-1242EIMS Cleartext Leak via edgserver (CWE-319) V1.06.01
CVE-2026-73174 Published on September 16, 2026

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Cleartext Transmission of Sensitive Information

The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. Many communication channels can be "sniffed" by attackers during data transmission. For example, network traffic can often be sniffed by any attacker who has access to a network interface. This significantly lowers the difficulty of exploitation by attackers.


Affected Versions

Advantech EKI-1242IEIMS: Advantech EKI-1242EIMS: