Advantech EKI-1524-CE series
Advantech EKI-1524-CE, EKI-1522-CE, and EKI-1521-CE series industrial Ethernet switches running firmware version 1.24 and earlier contain a cross-site scripting (XSS) vulnerability in the management web interface. An attacker with valid credentials could craft a malicious link that, when clicked by an authenticated user, executes arbitrary code within the user's session context. This could allow unauthorized modification of switch configuration, traffic redirection, or disruption of communications between connected industrial devices.
- Valid login credentials to the switch management interface
- Network access to the management port (typically port 80/443)
- User must click malicious link or open attachment while logged in
- User interaction required (not fully automated)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ccd55461-a9d4-4b74-aff2-c4520cd68c6eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.