Impact
XING CPTrans‑ME‑X is vulnerable to an operating‑system command injection flaw that allows an attacker to inject arbitrary commands without needing to authenticate. The vulnerability is classified as CWE‑78 and carries a CVSS score of 9.3, indicating a high severity that can compromise system integrity and confidentiality if exploited.
Affected Systems
The affected product is XING CPTrans‑ME‑X from Xing Inc. No specific version information is provided, so all installations of this product should be considered potentially vulnerable until verified.
Risk and Exploitability
The high CVSS rating, coupled with the fact that the flaw is exploitable remotely and unauthenticated, points to a significant risk of widespread impact if an attacker can reach the target. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog, so while the likelihood of exploitation in the wild is uncertain, the potential impact makes the vulnerability a high priority. Attackers could use the injection to execute arbitrary shell commands, potentially leading to full system compromise.
OpenCVE Enrichment