Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in ProSoft Technology cellular gateways could allow remote attackers to execute system commands, potentially gaining full control of the device. This issue is present in the web user interface and arises from improper handling of user input. The main concern is to confirm if these specific gateways are in use and exposed.
- Input errors allow remote command execution.
- Affects network-connected industrial gateways.
- Confirm relevance and exposure for your environment.
Attack Path
How an attacker could exploit the issue
An attacker could target cellular gateways exposed to the network, interacting with their web interface to submit specially crafted input. Because the interface does not properly validate this input, the attacker can inject and run system commands, potentially gaining full control of the device.
- Accessible via the network.
- Triggered by malicious web input.
- Allows remote command execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow remote attackers to execute arbitrary commands on affected cellular gateways when supported by the advisory. The web user interface, accessible over the network, could be exploited through unvalidated input fields to gain root privileges and compromise the device.
- System commands and root access at risk.
- Malicious input via unvalidated web fields.
- Device compromise and arbitrary command execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
ProSoft Technology ICX35-HWC cellular gateways are susceptible to remote command injection through their web interface. This critical vulnerability, which allows for root privilege escalation, is likely to affect infrastructure or operations teams responsible for managing industrial control systems and network edge devices. The immediate priority is to identify all instances of this gateway, determine their network exposure and business criticality, and assign ownership for remediation planning.
- Infrastructure and operations teams own this.
- Verify network exposure and criticality.
- Plan and coordinate remediation efforts.