Impact
The vulnerable System Clock component of RedPort Optimizer allows an attacker to inject arbitrary operating‑system commands through the exec function in datetime.php. The flaw is classified as CWE‑74 (Path Traversal) and CWE‑77 (Command Injection), and its CVSS score of 9.4 reflects a high‑severity risk of remote code execution.
Affected Systems
RedPort:Optimizer wXa‑203, wXa‑213, and wXa‑223 versions up to 20260704 are impacted. The attack surfaces the /xgatev1/system/datetime.php file of the System Clock module, and the vendor has not yet provided a public fix.
Risk and Exploitability
The vulnerability can be triggered remotely, and although the EPSS score is not available, the high CVSS and public disclosure indicate that exploitation is plausible. It is not listed in the CISA KEV catalog, yet the potential to run arbitrary commands on the host constitutes a significant threat.
OpenCVE Enrichment