Impact
This flaw allows a remote attacker to input malicious data into the web interface of ProSoft ICX35‑HWC gateways, causing the device to execute arbitrary system commands. The weakness arises from insufficient input validation and is classified as a command injection vulnerability (CWE‑78). The ability to run system commands grants the attacker full control over the gateway, potentially compromising the confidentiality, integrity, and availability of the device and any networks it serves.
Affected Systems
The vulnerability affects ProSoft Technology ICX35‑HWC Cellular Gateways that run firmware version 1.3 or earlier. Any gateway deployed with these firmware releases is susceptible and could allow an attacker to exploit the unvalidated web input.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. Although specific exploit probability data is not available, the flaw can be triggered remotely via the web interface without authentication, implying a high risk of exploitation. The vulnerability is not documented as actively exploited, but the severity and easy attack path warrant serious attention.
OpenCVE Enrichment