CVE-2017-20236Disclosure(prosoft-technology / icx35-hwc)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerability to gain root privileges and execute arbitrary commands on the device through the accessible web interface.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • icx35-hwc
  • icx35-hwc_firmware

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
icx35-hwcicx35-hwc_firmware

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-03: 2Technical Details · 2026-04-03: 204-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2017-20236: CRITICAL] Beware of ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways! A web interface vulnerability allows remote attackers to gain root privileges and execute commands.#cve,CVE-2017-20236,#cybersecurity https://cvefind.com/CVE-2017-20236

    Post summary

    The post announces a critical vulnerability (CVE‑2017‑20236) in ProSoft Technology ICX35‑HWC gateways, highlighting that remote attackers can obtain root access via the web interface. No exploit code, patch information, or active exploitation reports are mentioned.

    0001041
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2017-20236: ProSoft Technology ICX35-HWC Com... ProSoft ICX35 cellular gateways leak root shells through web UI command injection - zero-auth RCE with 9.8 CVSS makes t... https://zerodaysignal.com/vulnerability/CVE-2017-20236 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A zero‑auth RCE via UI command injection was disclosed for ProSoft ICX35 gateways (CVE‑2017‑20236, 9.8 CVSS); no exploitation activity, patch, or PoC details are provided.

    0000068
    204 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWprosoft-technologyicx35-hwc---
OSprosoft-technologyicx35-hwc_firmware---

Explore more