Impact
The CVE exposes an OS command injection in the firmware update route of Copeland XWEB Pro devices. An attacker who can authenticate to the device can inject arbitrary operating‑system commands, potentially taking full control of the embedded controller. The flaw allows the execution of commands from malicious input, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
The issue affects Copeland XWEB 300D Pro, XWEB 500B Pro, and XWEB 500D Pro models running firmware version 1.12.1 or earlier. These devices can be identified by the CPE strings listed under Copeland XWEB Pro firmware.
Risk and Exploitability
The CVSS score of 8.0 places the flaw in the high‐severity range, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. Exploitation requires authenticated access to the firmware update interface, so only users with valid credentials can attempt the injection. The vulnerability is not currently listed in the CISA KEV catalog, reducing the likelihood of widespread use by threat actors.
OpenCVE Enrichment