ProSoft Technology ICX35-HWC
cpe:2.3:h:prosoft-technology:icx35-hwc-a:*:*:*:*:*:*:*, +3 more
- <= 1.3
A command injection vulnerability has been identified in the web user interface of ProSoft Technology ICX35-HWC cellular gateways, affecting versions through 1.3. This vulnerability allows remote attackers to inject and execute system commands by exploiting unvalidated input fields in the web interface. Successful exploitation grants root privileges, enabling arbitrary command execution on the device. The vulnerability can be exploited remotely via the cellular network, potentially using the compromised device as a platform for broader attacks.
Exploitation of this vulnerability allows for arbitrary command execution on the device with root privileges. Given that the ICX35-HWC provides Internet connectivity through its cellular WAN port, a compromised gateway could be used as a launch point for attacks against other systems.
Users are advised to update the firmware on their ICX35-HWC gateways to version 1.3 or later. The firmware update can be performed through ProSoft Connect or by downloading the firmware files from the ProSoft Technology website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.