Input Validation Flaw in ProSoft Technology's Cellular Gateways
CVE-2017-20236
9.3CRITICAL
Key Information:
- Vendor
Prosoft Technology
- Vendor
- CVE Published:
- 3 April 2026
What is CVE-2017-20236?
ProSoft Technology's ICX35-HWC cellular gateways prior to version 1.3 are susceptible to an input validation vulnerability within their web user interface. This flaw enables remote attackers to exploit unvalidated input fields, facilitating the injection and execution of arbitrary system commands. By leveraging this vulnerability, attackers can acquire root privileges and execute unauthorized operations on the device through the compromised web interface, posing significant security risks to affected installations.
Affected Version(s)
ICX35-HWC Cellular Gateway 0 <= 1.3
