Impact
An unauthenticated attacker can exploit a flaw in the web user interface of ProSoft Technology ICX35‑HWC cellular gateways running firmware 1.3 or earlier to bypass the authentication routine. The vulnerability, classified as CWE‑287, enables the attacker to obtain full administrative privileges, allowing configuration changes, firmware upgrades, or the deployment of malicious settings that can jeopardize network integrity, confidentiality, or availability.
Affected Systems
The affected hardware is the ProSoft Technology ICX35‑HWC Cellular Gateway. Devices with firmware version 1.3 and any prior release are vulnerable. No other vendors or product lines are reported to be impacted.
Risk and Exploitability
The flaw carries a critical CVSS score of 9.3, indicating a severe threat if exploited. The EPSS score of < 1% indicates a very low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The attack vector most likely involves accessing the gateway’s web management interface over the local or Internet‑connected network, and the authentication bypass can be performed without any credentials or additional access privileges. Devices must be updated or otherwise isolated to mitigate the risk if a patch is not immediately available.
OpenCVE Enrichment