PT-2026-22261 · Xweb Pro · Xweb Pro

Amir Zaltzman

+1

·

Publicado

2026-02-27

·

Atualizado

2026-03-10

·

CVE-2026-25111

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWEB Pro versions prior to 1.12.1
Description An OS command injection issue exists that allows a logged-in attacker to execute code remotely on the system. This is achieved by submitting crafted input to the restore route. The restore route is susceptible to command injection due to improper input validation. The vulnerable parameter is not specified.
Recommendations Update XWEB Pro to a version later than 1.12.1.

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25111

Produtos afetados

Xweb Pro