CVE-2026-1222

HIGH

PrismX MX100 AP - RCE

Title source: llm
STIX 2.1

Description

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Scores

CVSS v3 7.2
EPSS 0.0032
EPSS Percentile 54.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
BROWAN COMMUNICATIONS/PrismX MX100 AP controller < 1.03.23.01
Published Jan 20, 2026
Tracked Since Feb 18, 2026