CVE-2026-25721

8.0

Copeland · XWEB Pro

An OS command injection vulnerability exists in Copeland XWEB Pro versions 1.12.1 and prior, allowing authenticated attackers to achieve remote code execution.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to execute arbitrary code, posing a severe risk of total system compromise.

Vulnerability

The vulnerability is an OS command injection (CWE-78) flaw triggered by injecting malicious input into the server username or password fields of the restore action within the API V1 route. An authenticated attacker with administrative privileges is required to trigger this execution.

Business impact

Successful exploitation grants an attacker the ability to execute arbitrary OS commands, leading to full system compromise, potential data exfiltration, or operational disruption of the affected industrial control units. With a CVSS score of 8.0, this high-severity vulnerability represents a significant risk to organizational infrastructure and integrity if the management interface is accessible to compromised or malicious user accounts.

Remediation

Immediate Action: Update the XWEB Pro firmware to the latest version via the official Copeland software update page or directly through the device system menu under System, Updates, Network.

Proactive Monitoring: Review system access logs for anomalous authentication patterns and monitor the API V1 route for suspicious POST requests containing unexpected command-line characters.

Compensating Controls: Restrict network access to the XWEB Pro management interface to trusted internal segments only, and implement strict identity and access management controls to prevent unauthorized use of administrative credentials.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for remote code execution, security teams must prioritize patching all instances of Copeland XWEB Pro within their environment. If an immediate update is not feasible, ensure that access to the management interface is strictly limited to authorized personnel to mitigate the risk of exploitation by malicious insiders or compromised accounts.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.