CVE-2026-84059
ICP DAS UA-2200/UA-5200 CGI ArmAngstromInstructionSet command injection
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Executing a manipulation of the argument ParameterArray can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-77 CWE-74 |
| Vendor | icp das |
| Product | ua-2200 |
| Published | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for icp das ua-2200
Be the first to know when new high vulnerabilities affecting icp das ua-2200 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
ICP DAS / UA-2200
20260704
ICP DAS / UA-5200
20260704
References
vuldb.com: https://vuldb.com/vuln/397547 vuldb.com: https://vuldb.com/vuln/397547/cti vuldb.com: https://vuldb.com/cve/CVE-2026-84059 vuldb.com: https://vuldb.com/submit/880065 vuldb.com: https://vuldb.com/submit/880072 uvxbywu62qm.feishu.cn: https://uvxbywu62qm.feishu.cn/wiki/SzRyw0uSnieCLDkMR8NcgcvanMd?from=from_copylink uvxbywu62qm.feishu.cn: https://uvxbywu62qm.feishu.cn/wiki/KwSzwcCstioZqKk7PODcIsDAn4W?from=from_copylink
Credits
๐ huliangjia (VulDB User) VulDB CNA Team