PT-2026-7658 · Copeland · Copeland Xweb 300D Pro+5

Amir Zaltzman

+1

·

Published

2026-02-11

·

Updated

2026-03-04

·

CVE-2026-21389

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWEB Pro versions prior to 1.12.1 MSHTML (affected versions not specified)
Description An OS command injection issue exists in XWEB Pro, allowing a user with network access to execute code remotely by injecting malicious input into the request body sent to the contacts import route. A memory corruption flaw has been actively exploited in MSHTML (Trident) through specially crafted web or HTML content, leading to code execution with the privileges of the current user. This affects global Windows systems, particularly those utilizing legacy Internet Explorer components within applications like Office or embedded web controls.
Recommendations Update XWEB Pro to version 1.12.1 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21389

Affected Products

Copeland Xweb 300D Pro
Copeland Xweb 500B Pro
Copeland Xweb 500D Pro
Xweb 300D Pro Firmware
Xweb 500B Pro Firmware
Xweb 500D Pro Firmware