CVE-2026-24695
8.0Copeland · XWEB Pro
An OS command injection vulnerability in Copeland XWEB Pro allows an authenticated attacker to achieve remote code execution by injecting malicious input into OpenSSL argument fields.
Executive summary
A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
The flaw is an OS command injection (CWE-78) occurring in the utility route. An authenticated attacker can trigger remote code execution by providing crafted input to OpenSSL argument fields.
Business impact
Successful exploitation allows an attacker to gain full control over the affected XWEB Pro unit, which may lead to unauthorized access to industrial control environments, data theft, or complete system compromise. With a CVSS score of 8.0, this high-severity vulnerability represents a significant risk to operational stability and security, particularly in environments where these units manage critical infrastructure.
Remediation
Immediate Action: Update the XWEB Pro firmware to the latest version via the Copeland software update page or directly through the device menu under SYSTEM, Updates, Network.
Proactive Monitoring: Review system logs for unusual activity or unauthorized command execution attempts, particularly those involving OpenSSL-related parameters.
Compensating Controls: Restrict network access to the XWEB Pro management interface to trusted administrative subnets only to minimize the risk of unauthorized authentication.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote code execution and the critical nature of the affected hardware, organizations should treat this vulnerability with high priority. Administrators must verify their software versions and apply the provided firmware updates immediately to ensure the security of their operational technology environment.
More Copeland CVEs
Sources
Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.