PT-2026-7658 · Copeland · Copeland Xweb 300D Pro+5
Amir Zaltzman
+1
·
Published
2026-02-11
·
Updated
2026-03-04
·
CVE-2026-21389
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWEB Pro versions prior to 1.12.1
MSHTML (affected versions not specified)
Description
An OS command injection issue exists in XWEB Pro, allowing a user with network access to execute code remotely by injecting malicious input into the request body sent to the contacts import route.
A memory corruption flaw has been actively exploited in MSHTML (Trident) through specially crafted web or HTML content, leading to code execution with the privileges of the current user. This affects global Windows systems, particularly those utilizing legacy Internet Explorer components within applications like Office or embedded web controls.
Recommendations
Update XWEB Pro to version 1.12.1 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Copeland Xweb 300D Pro
Copeland Xweb 500B Pro
Copeland Xweb 500D Pro
Xweb 300D Pro Firmware
Xweb 500B Pro Firmware
Xweb 500D Pro Firmware