---
id: CVE-2017-20235
title: >-
  ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain
  an authentication bypass vulnerability in the web user interface that allows
  unauthenticated attackers to gain access to administrative functions without
  valid …
summary: >-
  ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain
  an authentication bypass vulnerability in the web user interface that allows
  unauthenticated attackers to gain access to administrative functions without
  valid …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-287
vendor: prosoft-technology
product: icx35-hwc_firmware
affected:
  - icx35-hwc_firmware < 1.3
patched:
  - icx35-hwc_firmware 1.3
published: '2026-04-03'
updated: '2026-07-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-20235'
references:
  - url: >-
      https://assets.belden.com/m/1281cac2c9e90abf/original/Security-Bulletin-Authentication-Security-ProSoft-ICX35-BSECV-2017-09.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/prosoft-technology-icx35-hwc-authentication-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00451
epssPercentile: 0.38433
ingestedAt: '2026-07-21T16:51:40.807Z'
---

## Overview

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.

## Affected

- `icx35-hwc_firmware < 1.3`

## Remediation

Upgrade past the affected range:

- `icx35-hwc_firmware 1.3`
