ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerability to gain root privileges and execute arbitrary commands on the device through the accessible web interface.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prosoft-technology
Prosoft-technology icx35-hwc |
|
| Vendors & Products |
Prosoft-technology
Prosoft-technology icx35-hwc |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 04 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerability to gain root privileges and execute arbitrary commands on the device through the accessible web interface. | |
| Title | ProSoft Technology ICX35-HWC Command Injection via Web Interface | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-03T22:54:00.846Z
Updated: 2026-04-06T18:02:55.640Z
Reserved: 2026-04-03T19:07:31.394Z
Link: CVE-2017-20236
Updated: 2026-04-06T18:00:37.225Z
Status : Awaiting Analysis
Published: 2026-04-03T23:17:00.447
Modified: 2026-04-07T13:20:55.200
Link: CVE-2017-20236
No data.