PT-2026-7658 · Copeland · Copeland Xweb 300D Pro+5

Amir Zaltzman

+1

·

Publicado

2026-02-11

·

Atualizado

2026-03-04

·

CVE-2026-21389

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWEB Pro versions prior to 1.12.1 MSHTML (affected versions not specified)
Description An OS command injection issue exists in XWEB Pro, allowing a user with network access to execute code remotely by injecting malicious input into the request body sent to the contacts import route. A memory corruption flaw has been actively exploited in MSHTML (Trident) through specially crafted web or HTML content, leading to code execution with the privileges of the current user. This affects global Windows systems, particularly those utilizing legacy Internet Explorer components within applications like Office or embedded web controls.
Recommendations Update XWEB Pro to version 1.12.1 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21389

Produtos afetados

Copeland Xweb 300D Pro
Copeland Xweb 500B Pro
Copeland Xweb 500D Pro
Xweb 300D Pro Firmware
Xweb 500B Pro Firmware
Xweb 500D Pro Firmware