CVE-2026-25105
8.0Copeland · XWEB PRO
An OS command injection vulnerability in Copeland XWEB PRO allows authenticated attackers to achieve remote code execution via the Modbus command tool.
Executive summary
A critical OS command injection vulnerability in Copeland XWEB PRO versions 1.12.1 and prior allows authenticated attackers to execute arbitrary code on the system.
Vulnerability
The flaw is an OS command injection (CWE-78) triggered by injecting malicious input into parameters of the Modbus command tool within the debug route. Successful exploitation requires an authenticated attacker with high privileges.
Business impact
This vulnerability carries a CVSS score of 8.0, reflecting its high severity due to the potential for total system compromise. Successful exploitation grants an attacker the ability to execute remote code, which could lead to unauthorized data access, loss of system integrity, and complete operational disruption of the affected industrial control units.
Remediation
Immediate Action: Update all affected XWEB PRO devices to the latest firmware version via the official Copeland software update portal or directly through the device system menu.
Proactive Monitoring: Review system access logs for unauthorized attempts to access the debug route or unusual activity originating from the Modbus command tool interface.
Compensating Controls: Restrict network access to the XWEB PRO management interface to trusted administrative IP addresses only, and employ a Web Application Firewall to inspect traffic for command injection patterns.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent potential remote code execution. Administrators should prioritize applying the vendor-supplied firmware updates to all XWEB PRO units and ensure that administrative access to these systems is strictly controlled and monitored to reduce the attack surface.
More Copeland CVEs
Sources
Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.