{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ua-2200--20260704/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-84059"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["UA-2200 (\u003c= 20260704)","UA-5200 (\u003c= 20260704)"],"_cs_severities":["high"],"_cs_tags":["cve","command-injection","industrial-control-system","iiot","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["ICP DAS"],"content_html":"\u003cp\u003eCVE-2026-84059 is a critical command injection vulnerability affecting ICP DAS UA-2200 and UA-5200 series controllers running firmware versions up to 20260704. The vulnerability resides within the ArmAngstromInstructionSet function, which is triggered when processing input to the /CGI?RestApi=SetHostname endpoint. By manipulating the ParameterArray argument in a crafted HTTP request, an attacker can inject and execute arbitrary system commands on the underlying appliance. This flaw is remotely exploitable without authentication, and functional exploit code has been publicly released, increasing the risk of exploitation by opportunistic threat actors. Given the lack of a vendor response or patch availability, defenders must prioritize network-level segmentation to restrict access to the web interface of these devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise of the affected Industrial IoT (IIoT) controllers. This could lead to unauthorized control over connected industrial processes, exfiltration of sensitive configuration data, or the use of the devices as persistence points within the internal network. The scope affects all deployments of UA-2200 and UA-5200 series units that have not implemented strict ingress filtering to the management web interface.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict network access to the management web interface of all ICP DAS UA-2200 and UA-5200 controllers to authorized administrative subnets only.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule at the network layer (WAF or IDS) to monitor for malicious HTTP POST requests containing command injection patterns targeting the /CGI?RestApi=SetHostname endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor device logs for unexpected process execution or modifications to configuration files, as the vulnerability enables arbitrary command execution.\u003c/li\u003e\n\u003cli\u003eSegment these controllers into an isolated VLAN to limit lateral movement potential in the event of compromise.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T13:05:52Z","date_published":"2026-09-01T13:05:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84059/","summary":"An unauthenticated remote command injection vulnerability in the ArmAngstromInstructionSet function of ICP DAS UA-2200 and UA-5200 devices allows remote attackers to execute arbitrary code via the ParameterArray argument.","title":"Command Injection Vulnerability in ICP DAS UA-2200 and UA-5200","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84059/"}],"language":"en","title":"CraftedSignal Threat Feed - UA-2200 (\u003c= 20260704)","version":"https://jsonfeed.org/version/1.1"}