PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25109 Copeland CVE debrief

CVE-2026-25109 is a high-severity OS command injection issue reported in XWEB Pro version 1.12.1 and earlier. According to the CISA CSAF advisory published on 2026-02-26, an authenticated attacker can inject malicious input into the devices field while accessing the get setup route and achieve remote code execution on the system. The advisory says a fix is available and recommends updating to the latest version.

Vendor
Copeland
Product
XWEB 300D PRO
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-26
Original CVE updated
2026-02-26
Advisory published
2026-02-26
Advisory updated
2026-02-26

Who should care

Operators and administrators of XWEB Pro deployments, especially environments exposing the management interface to remote users or broader network segments. Security teams responsible for OT/industrial control system management interfaces should prioritize this advisory because it affects an authenticated path to remote code execution.

Technical summary

The source advisory describes an OS command injection weakness in XWEB Pro version 1.12.1 and prior. The vulnerable flow is tied to the get setup route, where malicious input in the devices field can be interpreted as a system command. The result is remote code execution by an authenticated attacker. The supplied CVSS 3.1 vector is AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H, which aligns with a network-reachable issue requiring high privileges but potentially impacting confidentiality, integrity, and availability across scope.

Defensive priority

High

Recommended defensive actions

  • Update XWEB Pro to the latest vendor-provided version using Copeland's software update page or the built-in SYSTEM -> Updates -> Network path if the device has internet access.
  • Restrict access to XWEB Pro management interfaces to trusted administrative networks and accounts only.
  • Review authentication and authorization controls around the get setup route and any administrative workflows that accept devices field input.
  • Monitor for unusual administrative activity, especially unexpected setup changes or command-like input handling in logs.
  • Validate that backup, recovery, and incident-response procedures are ready in case the management system is compromised.

Evidence notes

This debrief is based on the CISA CSAF advisory 'Copeland XWEB and XWEB Pro' (ICSA-26-057-10), published and modified on 2026-02-26. The advisory explicitly states that XWEB Pro version 1.12.1 and prior are affected, that the flaw is an OS command injection reachable through the get setup route and devices field, and that Copeland provides a fix. No KEV entry was included in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25109 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25109

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25109 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25109

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.