CVE-2026-25109

8.0

Copeland · XWEB Pro

An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution via the get setup route.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB Pro products allows authenticated attackers to achieve remote code execution, necessitating immediate firmware updates.

Vulnerability

This is an OS command injection flaw (CWE-78) occurring in the get setup route. An authenticated attacker with high privileges can inject malicious input into the devices parameter to execute arbitrary code on the underlying system.

Business impact

The ability to execute arbitrary OS commands on these devices poses a severe risk to operational technology environments. Successful exploitation could lead to full system compromise, unauthorized control of connected industrial equipment, or persistent unauthorized access, potentially resulting in significant operational downtime or safety hazards. The CVSS score of 8.0 reflects the high impact on confidentiality, integrity, and availability.

Remediation

Immediate Action: Update XWEB Pro firmware to the latest version via the official Copeland software update page or by using the system update feature available in the device menu under SYSTEM, Updates, Network.

Proactive Monitoring: Review device access logs for unauthorized attempts to access the get setup route or unusual command execution patterns originating from administrative accounts.

Compensating Controls: Restrict administrative access to the XWEB Pro management interface to trusted internal networks only, and utilize network segmentation to isolate these devices from the broader corporate environment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution and the critical nature of the affected hardware in industrial settings, administrators should prioritize applying the provided firmware updates immediately. Ensure that administrative credentials for XWEB Pro devices are managed securely and rotated regularly to prevent unauthorized access to the vulnerable functionality.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.