<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>UA-5200 (&lt;= 20260704) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ua-5200--20260704/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 13:05:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ua-5200--20260704/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection Vulnerability in ICP DAS UA-2200 and UA-5200</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84059/</link><pubDate>Tue, 01 Sep 2026 13:05:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84059/</guid><description>An unauthenticated remote command injection vulnerability in the ArmAngstromInstructionSet function of ICP DAS UA-2200 and UA-5200 devices allows remote attackers to execute arbitrary code via the ParameterArray argument.</description><content:encoded><![CDATA[<p>CVE-2026-84059 is a critical command injection vulnerability affecting ICP DAS UA-2200 and UA-5200 series controllers running firmware versions up to 20260704. The vulnerability resides within the ArmAngstromInstructionSet function, which is triggered when processing input to the /CGI?RestApi=SetHostname endpoint. By manipulating the ParameterArray argument in a crafted HTTP request, an attacker can inject and execute arbitrary system commands on the underlying appliance. This flaw is remotely exploitable without authentication, and functional exploit code has been publicly released, increasing the risk of exploitation by opportunistic threat actors. Given the lack of a vendor response or patch availability, defenders must prioritize network-level segmentation to restrict access to the web interface of these devices.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full system compromise of the affected Industrial IoT (IIoT) controllers. This could lead to unauthorized control over connected industrial processes, exfiltration of sensitive configuration data, or the use of the devices as persistence points within the internal network. The scope affects all deployments of UA-2200 and UA-5200 series units that have not implemented strict ingress filtering to the management web interface.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict network access to the management web interface of all ICP DAS UA-2200 and UA-5200 controllers to authorized administrative subnets only.</li>
<li>Deploy the provided Sigma rule at the network layer (WAF or IDS) to monitor for malicious HTTP POST requests containing command injection patterns targeting the /CGI?RestApi=SetHostname endpoint.</li>
<li>Monitor device logs for unexpected process execution or modifications to configuration files, as the vulnerability enables arbitrary command execution.</li>
<li>Segment these controllers into an isolated VLAN to limit lateral movement potential in the event of compromise.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve</category><category>command-injection</category><category>industrial-control-system</category><category>iiot</category><category>remote-code-execution</category></item></channel></rss>