External risk intelligence

Advantech EKI-1242EIMS OS Command Injection.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-73172

The vulnerability affects the edgserver management service on a specific industrial communication gateway, listening on a non-standard TCP port (5058). While it is network-reachable, such industrial gateway management services are typically intended for internal control networks or secured deployments rather than being directly exposed to the public internet by design.

OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a management service for industrial communication gateways, allowing remote attackers to execute commands with root privileges. This type of issue can potentially compromise the integrity and availability of industrial control systems if exploited.

  • A flaw lets attackers run commands on industrial gateways.
  • Understand if our industrial gateways are at risk.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted requests to the edgserver management service over TCP port 5058. This service, which is part of the device's firmware, is accessible remotely and does not require authentication. Successful exploitation allows the attacker to execute arbitrary operating system commands with root privileges, potentially leading to complete system compromise.

  • Network-accessible, no authentication needed.
  • Crafted requests to management service.
  • Arbitrary command execution as root.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could execute arbitrary operating system commands as root on the affected device. This could occur when crafted requests are sent to TCP port 5058, potentially impacting the device's configuration and operational integrity.

  • System commands could be executed.
  • Crafted requests to a specific port.
  • Unrestricted root command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical command injection vulnerability in the Advantech EKI-1242EIMS edgserver management service requires a coordinated response. Infrastructure or platform teams managing these industrial gateways should initiate an asset inventory to locate all instances. Simultaneously, network and security teams need to assess external exposure and business criticality of each identified device. Coordination with the vendor will be essential for understanding remediation timelines and potential workarounds.

  • Infrastructure or Platform teams own the issue.
  • Verify device location and network exposure.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Advantech EKI-1242EIMS?

The Advantech EKI-1242EIMS is an industrial communication gateway designed to connect serial devices to Ethernet networks. These gateways are essential for data transmission in industrial automation environments, acting as a bridge between legacy serial equipment and modern network infrastructures. The affected edgserver management service is a core component of its firmware used to oversee and configure these gateway operations.

What does CVE-2026-73172 mean?

This CVE represents a vulnerability classified as CWE-78, known as OS Command Injection. In plain terms, it means the software fails to properly sanitize inputs before processing them. Because of this, an attacker can insert their own system commands into a request, tricking the device into executing unauthorized actions with root-level privileges.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a specially crafted request to TCP port 5058 on the affected device. Because the management service does not require authentication, the attacker does not need a password or valid credentials to send these requests. The bug is only triggered through this specific network communication path; requests sent to other ports or services do not engage this specific injection vulnerability.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that while these devices are network-reachable via port 5058, they are typically deployed within internal control networks rather than directly on the public internet. However, if your network configuration allows external access to this port, the risk of unauthorized remote exploitation increases significantly. You should verify if these gateways are reachable from outside your protected environment.

What should I do to address this risk?

Your first step is to perform an inventory to identify all EKI-1242EIMS units in your environment. Once located, verify their network accessibility and ensure they are isolated from public exposure. Monitor official vendor channels for firmware updates or security advisories that provide official patches, and coordinate with your infrastructure teams to plan the application of these fixes.

References