CVE-2026-25109

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:copeland:xweb_500b_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_500b_pro:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:copeland:xweb_300d_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_300d_pro:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:copeland:xweb_500d_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_500d_pro:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-27 01:16

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25109

Mitre link : CVE-2026-25109

CVE.ORG link : CVE-2026-25109


JSON object : View

Products Affected

copeland

  • xweb_500b_pro
  • xweb_500d_pro_firmware
  • xweb_500d_pro
  • xweb_300d_pro_firmware
  • xweb_300d_pro
  • xweb_500b_pro_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')