CVE-2026-25195
8.0Copeland · XWEB Pro
An OS command injection vulnerability in Copeland XWEB Pro allows an authenticated attacker to achieve remote code execution by uploading a crafted firmware update file.
Executive summary
An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to execute arbitrary code, posing a critical risk to system integrity and control.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) occurring within the firmware update functionality. It requires the attacker to be authenticated with high privileges to supply a malicious firmware update file, which then triggers remote code execution on the underlying system.
Business impact
The ability to achieve remote code execution on industrial control hardware represents a severe risk to operational technology environments. A successful exploit could lead to full system compromise, loss of process control, unauthorized data access, and potential hardware damage. With a CVSS score of 8.0, the vulnerability is classified as High, reflecting the significant impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update XWEB Pro devices to the latest firmware version via the official Copeland software update page or directly through the device menu by navigating to SYSTEM, then Updates, then Network.
Proactive Monitoring: Review system access logs for any unauthorized or unusual firmware update attempts or modifications to system configuration files.
Compensating Controls: Ensure that access to the administrative interface is restricted to authorized personnel only and operate the device within a segmented network to minimize exposure to untrusted entities.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of potential remote code execution on these industrial devices, administrators must prioritize applying the vendor-supplied firmware updates. Ensure all XWEB Pro units are verified against the list of affected models and move to the latest version immediately to eliminate this command injection vector.
More Copeland CVEs
Sources
Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.