External risk intelligence

ProSoft ICX35-HWC Command Injection via Web Interface

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2017-20236

The affected product is a cellular gateway designed for network connectivity. The vulnerability resides in the web user interface, which is a management surface intended to be accessible for device configuration. Such gateways are commonly deployed as internet-facing or edge devices, making the web interface frequently reachable from the network.

OS Command Injection

Prosoft Technology Icx35 Hwc Firmware

before 1.3

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in ProSoft Technology cellular gateways could allow remote attackers to execute system commands, potentially gaining full control of the device. This issue is present in the web user interface and arises from improper handling of user input. The main concern is to confirm if these specific gateways are in use and exposed.

  • Input errors allow remote command execution.
  • Affects network-connected industrial gateways.
  • Confirm relevance and exposure for your environment.

Attack Path

How an attacker could exploit the issue

An attacker could target cellular gateways exposed to the network, interacting with their web interface to submit specially crafted input. Because the interface does not properly validate this input, the attacker can inject and run system commands, potentially gaining full control of the device.

  • Accessible via the network.
  • Triggered by malicious web input.
  • Allows remote command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow remote attackers to execute arbitrary commands on affected cellular gateways when supported by the advisory. The web user interface, accessible over the network, could be exploited through unvalidated input fields to gain root privileges and compromise the device.

  • System commands and root access at risk.
  • Malicious input via unvalidated web fields.
  • Device compromise and arbitrary command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

ProSoft Technology ICX35-HWC cellular gateways are susceptible to remote command injection through their web interface. This critical vulnerability, which allows for root privilege escalation, is likely to affect infrastructure or operations teams responsible for managing industrial control systems and network edge devices. The immediate priority is to identify all instances of this gateway, determine their network exposure and business criticality, and assign ownership for remediation planning.

  • Infrastructure and operations teams own this.
  • Verify network exposure and criticality.
  • Plan and coordinate remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ProSoft Technology ICX35-HWC?

The ICX35-HWC is a cellular gateway used for industrial network connectivity. These devices act as a bridge, allowing remote equipment to communicate over cellular networks. They are typically used in field environments to provide secure data links for industrial control systems and other hardware that requires reliable, mobile network access.

How does this vulnerability allow command execution?

This issue is a form of command injection, categorized as CWE-78. It occurs because the device's web management interface fails to properly filter or sanitize user input in its fields. Because the system treats this unvalidated input as executable instructions, an attacker can supply malicious commands that the device then runs with root-level privileges.

What triggers the command injection on this gateway?

The vulnerability is triggered when an attacker submits specially crafted, malicious input into specific fields within the web user interface. It is important to note that actions taken through legitimate, non-malicious administrative configurations do not trigger this flaw. The risk specifically requires an attacker to provide input designed to break out of the intended data fields and invoke system-level commands.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal identifies this gateway as a device often deployed at the network edge to provide connectivity, which frequently makes the web management interface reachable over the internet. Because the vulnerability exists in the web UI, devices that are configured to allow web access from outside the local network are at a much higher risk of remote exploitation.

What should I do if I manage these gateways?

Your first step is to locate all instances of the ICX35-HWC within your infrastructure. Once identified, evaluate whether these devices need to be reachable over the network and restrict web interface access if it is not required for daily operations. Coordinate with your technical team to prioritize these assets for a review and follow the manufacturer's guidance for securing or updating your firmware.

References