PT-2026-22261 · Xweb Pro · Xweb Pro
Amir Zaltzman
+1
·
Published
2026-02-27
·
Updated
2026-03-10
·
CVE-2026-25111
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWEB Pro versions prior to 1.12.1
Description
An OS command injection issue exists that allows a logged-in attacker to execute code remotely on the system. This is achieved by submitting crafted input to the restore route. The
restore route is susceptible to command injection due to improper input validation. The vulnerable parameter is not specified.Recommendations
Update XWEB Pro to a version later than 1.12.1.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xweb Pro