Description
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
Published: 2026-09-04
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The XING CPTrans-ME-X device has a vulnerability that allows an attacker to expose sensitive system information to an unauthorized control sphere. This flaw can lead to the leakage of confidential system data, potentially allowing attackers to gain deeper insight into the device’s configuration or environment. The weakness is identified as CWE-497, which generally indicates a failure to protect sensitive data from unauthorized disclosure.

Affected Systems

The affected product is XING CPTrans-ME-X. No specific revision or firmware version information is given in the advisory, so all deployed variants of the CPTrans-ME-X may be at risk until official guidance is obtained.

Risk and Exploitability

The CVSS score of 8.7 denotes a high severity and indicates significant risk to confidentiality. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the current exploitation likelihood cannot be quantified precisely. The attack vector is not explicitly defined in the data; it is therefore inferred that the flaw could be exploited from the same network or system the device is connected to, or potentially from a remote management interface if exposed.

Generated by OpenCVE AI on September 4, 2026 at 08:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest XING CPTrans-ME-X patch or firmware update from the vendor.
  • Limit network access to the device’s control interface so that only trusted management stations can query it.
  • Implement strict access controls and monitor logs for unauthorized attempts to retrieve sensitive system data.

Generated by OpenCVE AI on September 4, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Sensitive System Information Leakage in XING CPTrans-ME-X

Fri, 04 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
Weaknesses CWE-497
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-04T06:31:44.601Z

Reserved: 2026-08-10T01:32:19.104Z

Link: CVE-2026-66840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T07:17:09.210

Modified: 2026-09-04T07:17:09.210

Link: CVE-2026-66840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T08:30:16Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere