Copeland XWEB and XWEB Pro OS Command Injection
Summary
| CVE | CVE-2026-25109 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-02-27 01:16:19 UTC |
| Updated | 2026-06-04 22:16:52 UTC |
| Description | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.002820000 probability, percentile 0.518590000 (date 2026-06-04)
Problem Types: CWE-78 | CWE-78 CWE-78
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 8 | HIGH | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8 | HIGH | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Copeland | Xweb 300d Pro | - | All | All | All |
| Operating System | Copeland | Xweb 300d Pro Firmware | All | All | All | All |
| Hardware | Copeland | Xweb 500b Pro | - | All | All | All |
| Operating System | Copeland | Xweb 500b Pro Firmware | All | All | All | All |
| Hardware | Copeland | Xweb 500d Pro | - | All | All | All |
| Operating System | Copeland | Xweb 500d Pro Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Copeland | Copeland XWEB 300D PRO | affected 1.12.1 custom | Not specified |
| CNA | Copeland | Copeland XWEB 500D PRO | affected 1.12.1 custom | Not specified |
| CNA | Copeland | Copeland XWEB 500B PRO | affected 1.12.1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-05... | [email protected] | github.com | Third Party Advisory |
| www.cisa.gov/news-events/ics-advisories/icsa-26-057-10 | [email protected] | www.cisa.gov | Third Party Advisory, US Government Resource |
| webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate | [email protected] | webapps.copeland.com | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA. (en)
Additional Advisory Data
Solutions
CNA: Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.
CNA: Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.