CVE-2026-24689

8.0

Copeland · XWEB Pro

An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution via the firmware update apply action.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated remote attackers to execute arbitrary code on affected devices.

Vulnerability

This is an OS command injection vulnerability (CWE-78) occurring in the firmware update function. An attacker with authenticated access can inject malicious commands into the devices field, resulting in remote code execution with high privileges.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected industrial control system hardware. Given the CVSS score of 8.0, this represents a high-severity risk that could lead to unauthorized system modification, total loss of confidentiality, and potential disruption of critical operational processes.

Remediation

Immediate Action: Update the XWEB Pro firmware to the latest version by visiting the official Copeland software update page or by performing an update directly through the device menu under SYSTEM, Updates, Network.

Proactive Monitoring: Review system access logs for unauthorized administrative sessions and monitor for unusual network activity originating from the XWEB Pro management interface.

Compensating Controls: Restrict network access to the XWEB Pro management interface to trusted administrative IP addresses only, and ensure that management traffic is isolated from public-facing networks.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this command injection flaw necessitates immediate remediation. Organizations should identify all deployed Copeland XWEB Pro units and prioritize the firmware update process to eliminate the remote execution risk. Failure to patch these devices leaves critical infrastructure exposed to potential compromise by authorized users or compromised accounts.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.