CVE-2026-25196
8.0Copeland · XWEB Pro
An OS command injection vulnerability in Copeland XWEB Pro versions 1.12.1 and prior allows authenticated attackers to achieve remote code execution via malicious Wi-Fi configuration input.
Executive summary
A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution, posing a significant risk to system integrity and control.
Vulnerability
The vulnerability is an OS command injection flaw (CWE-78) triggered by injecting malicious input into the Wi-Fi SSID or password configuration fields. This requires the attacker to have high privileges (authenticated access) to the management interface to execute arbitrary code on the underlying system.
Business impact
The ability for an attacker to achieve remote code execution on these industrial control devices could lead to total system compromise, unauthorized access to sensitive operational data, or the disruption of critical facility management processes. With a CVSS score of 8.0, this high-severity vulnerability represents a significant risk to operational continuity and security, particularly in OT environments where these devices are typically deployed.
Remediation
Immediate Action: Update the XWEB Pro system to the latest version by visiting the official Copeland software update page or by navigating to the System, Updates, and Network menu within the device interface.
Proactive Monitoring: Monitor system logs for unauthorized configuration changes or attempts to modify network settings, especially those involving SSID or password fields.
Compensating Controls: Restrict administrative access to the XWEB Pro management interface to trusted internal networks only, and implement strict network segmentation to limit the potential blast radius of a compromised device.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Given the potential for remote code execution and the critical nature of the affected hardware, organizations should treat this update as a high-priority task. Administrators must verify their current version and apply the vendor-provided firmware update immediately to prevent potential exploitation of the command injection vector.
More Copeland CVEs
Sources
Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.