← Back

CVE-2026-20764

nvd nist
Published: Feb 27, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname configuration which is later processed during system setup, resulting in remote code execution.

Affected (3)

3 products
Xweb 300d Pro Firmware
Xweb 500d Pro Firmware
Xweb 500b Pro Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12.1
Running on/withPlatform Versions
Copeland
Xweb 300d Pro
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12.1
Running on/withPlatform Versions
Copeland
Xweb 500d Pro
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12.1
Running on/withPlatform Versions
Copeland
Xweb 500b Pro
All versions

References (3)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.