PT-2026-84140 · Icpdas · Ua-5200+1

·

CVE-2026-84059

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ICP DAS UA-2200 versions prior to 20260704 ICP DAS UA-5200 versions prior to 20260704
Description A remote command injection flaw exists in the ArmAngstromInstructionSet() function within the '/CGI?RestApi=SetHostname' endpoint. This issue occurs when the ParameterArray argument is manipulated, allowing an attacker to execute arbitrary commands on the system.
Recommendations Update ICP DAS UA-2200 to a version newer than 20260704. Update ICP DAS UA-5200 to a version newer than 20260704. As a temporary workaround, restrict access to the '/CGI?RestApi=SetHostname' endpoint to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84059

Affected Products

Ua-2200
Ua-5200