CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-24663

CVSS 9.0v3.1pub. 2026-02-27upd. 2026-03-09

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.

🤖 AI Analysis
How it works

The attacker sends a crafted network request to the endpoint responsible for library installation in the XWEB Pro system. In the request body, they inject malicious operating system commands, which are then executed by the vulnerable component without proper validation and sanitization of input data. The attack is possible remotely over the network without the need to possess an account in the system.

Impact

Successful exploitation of the vulnerability gives the attacker full control over the device through remote code execution (RCE) with operating system privilege level, which may lead to violations of confidentiality, integrity, and system availability.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references — update available at https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate. It is also recommended to limit network access to XWEB Pro devices through a firewall and to isolate the OT network from corporate networks and the Internet.

Who is affected

Copeland XWEB Pro in version 1.12.1 and earlier — affects Copeland Xweb 500B Pro, Copeland Xweb 300D Pro, and Copeland Xweb 500D Pro devices (firmware and software).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Copeland Xweb 300d Pro

    HW
    Copeland
    all versions
  • Copeland Xweb 300d Pro Firmware

    OS
    Copeland
    ≤ 1.12.1
  • Copeland Xweb 500b Pro

    HW
    Copeland
    all versions
  • Copeland Xweb 500b Pro Firmware

    OS
    Copeland
    ≤ 1.12.1
  • Copeland Xweb 500d Pro

    HW
    Copeland
    all versions
  • Copeland Xweb 500d Pro Firmware

    OS
    Copeland
    ≤ 1.12.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2026-21718CRITICAL10.0PL ✓same product

Auth Bypass i RCE w Copeland XWEB Pro – firmware sterowników przemysłowych

CVE-2026-20742HIGH8.0same product

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticate...

CVE-2026-20902HIGH8.0same product

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authentica...

CVE-2026-20910HIGH8.0same product

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated...

CVE-2026-20764HIGH8.0same product

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated...