ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prosoft-technology
Prosoft-technology icx35-hwc |
|
| Vendors & Products |
Prosoft-technology
Prosoft-technology icx35-hwc |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 04 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings. | |
| Title | ProSoft Technology ICX35-HWC Authentication Bypass | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-03T22:51:42.963Z
Updated: 2026-04-06T16:07:41.199Z
Reserved: 2026-04-03T18:52:46.939Z
Link: CVE-2017-20235
Updated: 2026-04-06T16:07:38.263Z
Status : Awaiting Analysis
Published: 2026-04-03T23:17:00.267
Modified: 2026-04-07T13:20:55.200
Link: CVE-2017-20235
No data.