CVE-2026-1222

HIGH

PrismX MX100 AP controller < 1.03.23.01 - Authenticated Arbitrary File Upload

Title source: llm
STIX 2.1

Description

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-10642-3b808-1.html
Various Sources third-party-advisory
https://www.twcert.org.tw/en/cp-139-10643-2f8d7-2.html

Scores

CVSS v3 7.2
EPSS 0.0057
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
BROWAN COMMUNICATIONS/PrismX MX100 AP controller < 1.03.23.01
Published Jan 20, 2026
Tracked Since Feb 18, 2026