Impact
A flaw in the ArmAngstromInstructionSet function of the /CGI?RestApi=SetHostname endpoint allows an attacker to inject and execute arbitrary system commands. This command injection can compromise confidentiality, integrity, and availability of the target device, leading to full compromise of the affected system. The weakness involves improper handling of the ParameterArray argument and unsafe command construction, as described by CWE-74 and CWE-77.
Affected Systems
Affected products are ICP DAS UA‑2200 and UA‑5200 firmware versions up to 20260704. No other versions or products are listed as vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity. EPSS data is not available and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack can be performed remotely, and published exploits exist, meaning an adversary could remotely trigger the command injection without local access.
OpenCVE Enrichment