Executive brief
ICP DAS manufactures remote I/O and industrial automation controllers used in manufacturing and SCADA environments. A command injection vulnerability in the SetHostname API allows unauthenticated remote attackers to execute arbitrary system commands on affected devices, potentially compromising operational technology infrastructure and enabling lateral movement into critical systems.
Technical details
The vulnerability exists in the ArmAngstromInstructionSet function within the /CGI?RestApi=SetHostname endpoint of ICP DAS UA-2200 and UA-5200 devices. The ParameterArray argument is not properly sanitized, allowing attackers to inject arbitrary shell commands that are executed with device privileges. The attack is network-accessible and requires no authentication or user interaction. An attacker can achieve remote code execution on the affected industrial controller. The vendor was contacted early but did not respond or provide patches.
Affected products
- ICP DAS UA-2200 up to 20260704
- ICP DAS UA-5200 up to 20260704
Timeline
- 2026-09-01: disclosed
- exploited: Exploit has been published and may be used in the wild