PT-2026-84140 · Icpdas · Ua-5200+1
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ICP DAS UA-2200 versions prior to 20260704
ICP DAS UA-5200 versions prior to 20260704
Description
A remote command injection flaw exists in the
ArmAngstromInstructionSet() function within the '/CGI?RestApi=SetHostname' endpoint. This issue occurs when the ParameterArray argument is manipulated, allowing an attacker to execute arbitrary commands on the system.Recommendations
Update ICP DAS UA-2200 to a version newer than 20260704.
Update ICP DAS UA-5200 to a version newer than 20260704.
As a temporary workaround, restrict access to the '/CGI?RestApi=SetHostname' endpoint to minimize the risk of exploitation.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ua-2200
Ua-5200