Description
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
Published: 2026-09-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

XING CPTrans‑ME‑X is vulnerable to an operating‑system command injection flaw that allows an attacker to inject arbitrary commands without needing to authenticate. The vulnerability is classified as CWE‑78 and carries a CVSS score of 9.3, indicating a high severity that can compromise system integrity and confidentiality if exploited.

Affected Systems

The affected product is XING CPTrans‑ME‑X from Xing Inc. No specific version information is provided, so all installations of this product should be considered potentially vulnerable until verified.

Risk and Exploitability

The high CVSS rating, coupled with the fact that the flaw is exploitable remotely and unauthenticated, points to a significant risk of widespread impact if an attacker can reach the target. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog, so while the likelihood of exploitation in the wild is uncertain, the potential impact makes the vulnerability a high priority. Attackers could use the injection to execute arbitrary shell commands, potentially leading to full system compromise.

Generated by OpenCVE AI on September 4, 2026 at 08:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or update to XING CPTrans‑ME‑X as soon as it becomes available.
  • If a patch is not yet released, limit network access to the product so that only authorized hosts can reach it, effectively preventing unauthenticated exploitation.
  • Configure firewalls or reverse proxies to block unexpected or malformed requests that could trigger command injection, and monitor logs for signs of injection attempts.

Generated by OpenCVE AI on September 4, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated OS Command Injection in XING CPTrans-ME-X

Fri, 04 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
Weaknesses CWE-78
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-04T06:31:37.342Z

Reserved: 2026-08-10T01:32:18.184Z

Link: CVE-2026-62928

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T07:17:09.057

Modified: 2026-09-04T07:17:09.057

Link: CVE-2026-62928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T08:30:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')