Copeland
Copeland Xweb 500b PRO Firmware: vulnerabilidades y CVE
Copeland Xweb 500b PRO Firmware tiene 23 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses23
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-3037 | Alta (8.8) | 2.6% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird… |
| CVE-2026-25721 | Alta (8.8) | 2.6% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server username… |
| CVE-2026-25196 | Alta (8.8) | 1.9% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID… |
| CVE-2026-25105 | Alta (8.8) | 1.9% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the… |
| CVE-2026-25037 | Alta (8.8) | 1.9% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which… |
| CVE-2026-24452 | Alta (8.8) | 1.9% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices… |
| CVE-2026-23702 | Alta (8.8) | 1.9% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server… |
| CVE-2026-22877 | Crítica (9.1) | 0.57% | — | 27 feb 2026 | An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack. |
| CVE-2026-20797 | Crítica (9.8) | 0.81% | — | 27 feb 2026 | A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program. |
| CVE-2026-20764 | Alta (8.8) | 2.0% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname… |
| CVE-2026-25195 | Media (6.6) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the… |
| CVE-2026-25111 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the… |
| CVE-2026-25109 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field… |
| CVE-2026-25085 | Crítica (9.8) | 0.50% | — | 27 feb 2026 | A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication… |
| CVE-2026-24695 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument… |
| CVE-2026-24689 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of… |
| CVE-2026-24663 | Crítica (9.8) | 2.2% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries… |
| CVE-2026-24517 | Alta (7.2) | 1.6% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the… |
| CVE-2026-21718 | Crítica (9.8) | 0.44% | — | 27 feb 2026 | An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system. |
| CVE-2026-21389 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body… |
| CVE-2026-20910 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of… |
| CVE-2026-20902 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename… |
| CVE-2026-20742 | Alta (8.8) | 1.5% | — | 27 feb 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.