CVE-2026-25037

8.0

Copeland · XWEB Pro

An OS command injection vulnerability in Copeland XWEB Pro versions 1.12.1 and prior allows an authenticated attacker to achieve remote code execution via a maliciously crafted LCD state.

Executive summary

An OS command injection vulnerability in Copeland XWEB Pro allows an authenticated attacker to gain remote code execution, posing a high risk to operational technology environments.

Vulnerability

This is an OS command injection flaw (CWE-78) triggered by a maliciously crafted LCD state. The vulnerability requires an authenticated attacker to configure the state, which is then processed during system setup to execute arbitrary commands.

Business impact

The ability for an attacker to achieve remote code execution (RCE) on an XWEB Pro system represents a critical threat to industrial control environments. With a CVSS score of 8.0, the vulnerability enables unauthorized control over the affected device, potentially leading to full system compromise, loss of process integrity, and significant operational downtime.

Remediation

Immediate Action: Update the XWEB Pro firmware to the latest version via the official Copeland software update portal or directly through the device system menu under SYSTEM, Updates, Network.

Proactive Monitoring: Review system access logs for unauthorized configuration changes or suspicious activity related to the LCD state settings.

Compensating Controls: Restrict administrative access to the XWEB Pro management interface to authorized personnel only, and implement network segmentation to isolate these controllers from untrusted network segments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of potential RCE in an industrial setting, administrators should prioritize the firmware update process across all affected XWEB Pro units. Ensure that access controls are strictly enforced to prevent unauthorized users from reaching the administrative functions required to trigger this injection flaw.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.