CVE-2026-25085

8.6

Copeland · XWEB Pro

A vulnerability in Copeland XWEB Pro allows unauthenticated attackers to bypass authentication due to improper handling of return values in the authentication routine.

Executive summary

A critical authentication bypass vulnerability in Copeland XWEB Pro products allows unauthenticated remote attackers to gain unauthorized access to affected systems.

Vulnerability

This flaw, categorized under CWE-394, occurs when an unexpected return value from the authentication routine is processed as a legitimate success signal, effectively allowing an unauthenticated user to bypass the login process.

Business impact

The vulnerability carries a CVSS score of 8.6, indicating a high severity risk. Successful exploitation grants attackers unauthorized access to the XWEB Pro management interface, which could lead to the compromise of sensitive industrial control data, unauthorized modification of system settings, or potential disruption of operational processes.

Remediation

Immediate Action: Update the XWEB Pro firmware to the latest version via the official Copeland software update portal or directly through the device menu under SYSTEM, Updates, Network.

Proactive Monitoring: Review system access logs for unauthorized administrative logins or suspicious activity originating from unexpected IP addresses.

Compensating Controls: Restrict access to the XWEB Pro management interface by placing the device behind a secure VPN or firewall, ensuring it is not directly exposed to the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical nature of an authentication bypass in industrial control environments, administrators should prioritize this update immediately. Ensure all affected XWEB Pro units are patched to the latest version to prevent potential remote exploitation.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.