cvedb.io
CVE-2017-20235
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2026-04-03T23:17:00.267 · Last modified 2026-07-21T07:10:00.117

Summary

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.

Affected products

prosoft-technology — icx35-hwc_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when prosoft-technology ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.