CVE-2026-25111

8.0

Copeland · XWEB Pro

An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to execute remote code by injecting malicious input into the restore route.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution, potentially leading to a total system compromise.

Vulnerability

This is an OS command injection vulnerability (CWE-78) triggered via the restore route. It requires the attacker to have authenticated access to the system to successfully inject malicious input.

Business impact

The ability for an attacker to execute arbitrary OS commands represents a critical security risk, as it allows for full control over the affected device. Given the CVSS score of 8.0, this vulnerability could lead to unauthorized data access, complete loss of system integrity, and significant operational downtime in critical infrastructure environments.

Remediation

Immediate Action: Update the XWEB Pro firmware to the latest version by visiting the official Copeland software update portal or by using the system update feature available in the device management menu.

Proactive Monitoring: Monitor network and system logs for suspicious activity targeting the restore functionality or unusual outbound connections originating from the XWEB Pro hardware.

Compensating Controls: Restrict access to the XWEB Pro administrative interface to trusted management networks only and ensure that all administrative accounts are secured with strong, unique credentials.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk to operational technology environments due to the potential for remote code execution. Administrators should prioritize updating their XWEB Pro units immediately to the latest available version provided by Copeland to eliminate this command injection vector.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.