Description
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.
Published: 2026-04-03
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker can exploit a flaw in the web user interface of ProSoft Technology ICX35‑HWC cellular gateways running firmware 1.3 or earlier to bypass the authentication routine. The vulnerability, classified as CWE‑287, enables the attacker to obtain full administrative privileges, allowing configuration changes, firmware upgrades, or the deployment of malicious settings that can jeopardize network integrity, confidentiality, or availability.

Affected Systems

The affected hardware is the ProSoft Technology ICX35‑HWC Cellular Gateway. Devices with firmware version 1.3 and any prior release are vulnerable. No other vendors or product lines are reported to be impacted.

Risk and Exploitability

The flaw carries a critical CVSS score of 9.3, indicating a severe threat if exploited. The EPSS score of < 1% indicates a very low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The attack vector most likely involves accessing the gateway’s web management interface over the local or Internet‑connected network, and the authentication bypass can be performed without any credentials or additional access privileges. Devices must be updated or otherwise isolated to mitigate the risk if a patch is not immediately available.

Generated by OpenCVE AI on May 12, 2026 at 22:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware release from ProSoft Technology that fixes the authentication bypass flaw
  • Disable external access to the gateway’s web management interface and restrict management traffic to trusted internal networks if a firmware upgrade is not immediately possible
  • Deploy network segmentation or firewall rules to block unauthenticated access to the device’s web UI

Generated by OpenCVE AI on May 12, 2026 at 22:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Wed, 22 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Prosoft-technology icx35-hwc Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:prosoft-technology:icx35-hwc:-:*:*:*:*:*:*:*
cpe:2.3:o:prosoft-technology:icx35-hwc_firmware:*:*:*:*:*:*:*:*
Vendors & Products Prosoft-technology icx35-hwc Firmware

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Prosoft-technology
Prosoft-technology icx35-hwc
Vendors & Products Prosoft-technology
Prosoft-technology icx35-hwc

Mon, 06 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 04 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.
Title ProSoft Technology ICX35-HWC Authentication Bypass
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Prosoft-technology Icx35-hwc Icx35-hwc Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-14T02:06:28.187Z

Reserved: 2026-04-03T18:52:46.939Z

Link: CVE-2017-20235

cve-icon Vulnrichment

Updated: 2026-04-06T16:07:38.263Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-03T23:17:00.267

Modified: 2026-04-22T15:13:25.223

Link: CVE-2017-20235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T22:45:15Z

Weaknesses