CVE-2017-20236 PUBLISHED

ProSoft Technology ICX35-HWC Command Injection via Web Interface

Assigner: VulnCheck
Reserved: 03.04.2026 Published: 03.04.2026 Updated: 03.04.2026

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerability to gain root privileges and execute arbitrary commands on the device through the accessible web interface.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor ProSoft Technology
Product ICX35-HWC Cellular Gateway
Versions Default: affected
  • affected from 0 to 1.0 (incl.)
  • affected from 0 to 1.1 (incl.)
  • affected from 0 to 1.1d (incl.)
  • affected from 0 to 1.2.x (incl.)
  • Version 1.3 is unaffected

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CWE