← Back

CVE-2026-23702

nvd nist
Published: Feb 27, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route.

Affected (3)

3 products
Xweb 300d Pro Firmware
Xweb 500d Pro Firmware
Xweb 500b Pro Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12.1
Running on/withPlatform Versions
Copeland
Xweb 300d Pro
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12.1
Running on/withPlatform Versions
Copeland
Xweb 500d Pro
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12.1
Running on/withPlatform Versions
Copeland
Xweb 500b Pro
All versions

References (3)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.