OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-73172

CRITICAL · CVSS 9.3 EPSS 2.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical OS command injection vulnerability exists in the edgserver management service of Advantech EKI-1242EIMS, allowing remote unauthenticated attackers to execute arbitrary commands with root privileges through specially crafted requests to TCP port 5058. This poses a significant risk to the integrity and security of affected systems, potentially leading to full system compromise. Organizations using this firmware version should prioritize immediate patching or mitigation efforts to safeguard against potential exploitation.

CVE
CVE-2026-73172
Severity
CRITICAL
CVSS
9.3
EPSS
2.19%

Original NVD Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.