---
id: CVE-2017-20236
title: >-
  ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain
  an input validation vulnerability in the web user interface that allows remote
  attackers to inject and execute system commands by submitting malicious input
  th…
summary: >-
  ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain
  an input validation vulnerability in the web user interface that allows remote
  attackers to inject and execute system commands by submitting malicious input
  th…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: prosoft-technology
product: icx35-hwc_firmware
affected:
  - icx35-hwc_firmware < 1.3
patched:
  - icx35-hwc_firmware 1.3
published: '2026-04-03'
updated: '2026-07-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-20236'
references:
  - url: >-
      https://assets.belden.com/m/1116a05ab702b2ba/original/Security-Bulletin-User-Interface-ProSoft-ICX35-BSECV-2017-10.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/prosoft-technology-icx35-hwc-command-injection-via-web-interface
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00683
epssPercentile: 0.50679
ingestedAt: '2026-07-21T16:51:40.830Z'
---

## Overview

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerability to gain root privileges and execute arbitrary commands on the device through the accessible web interface.

## Affected

- `icx35-hwc_firmware < 1.3`

## Remediation

Upgrade past the affected range:

- `icx35-hwc_firmware 1.3`
