Description
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
Published: 2026-09-04
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Leakage
Action: Immediate Patch
AI Analysis

Impact

The XING CPTrans-ME-X device has a vulnerability that allows an attacker to expose sensitive system information to an unauthorized control sphere. This flaw can lead to the leakage of confidential system data, potentially allowing attackers to gain deeper insight into the device’s configuration or environment. The weakness is identified as CWE-497, which generally indicates a failure to protect sensitive data from unauthorized disclosure.

Affected Systems

The affected product is XING CPTrans-ME-X. No specific revision or firmware version information is given in the advisory, so all deployed variants of the CPTrans-ME-X may be at risk until official guidance is obtained.

Risk and Exploitability

The CVSS score of 8.7 denotes a high severity and indicates significant risk to confidentiality. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the current exploitation likelihood cannot be quantified precisely. The attack vector is not explicitly defined in the data; it is therefore inferred that the flaw could be exploited from the same network or system the device is connected to, or potentially from a remote management interface if exposed.

Generated by OpenCVE AI on September 4, 2026 at 08:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest XING CPTrans-ME-X patch or firmware update from the vendor.
  • Limit network access to the device’s control interface so that only trusted management stations can query it.
  • Implement strict access controls and monitor logs for unauthorized attempts to retrieve sensitive system data.

Generated by OpenCVE AI on September 4, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Xing
Xing xing Cptrans-me-x
Vendors & Products Xing
Xing xing Cptrans-me-x

Fri, 04 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Sensitive System Information Leakage in XING CPTrans-ME-X

Fri, 04 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
Weaknesses CWE-497
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Xing Xing Cptrans-me-x
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-04T19:45:07.623Z

Reserved: 2026-08-10T01:32:19.104Z

Link: CVE-2026-66840

cve-icon Vulnrichment

Updated: 2026-09-04T19:45:01.107Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T07:17:09.210

Modified: 2026-09-08T18:38:19.590

Link: CVE-2026-66840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:20:28Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere