Description
A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-31
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerable System Clock component of RedPort Optimizer allows an attacker to inject arbitrary operating‑system commands through the exec function in datetime.php. The flaw is classified as CWE‑74 (Path Traversal) and CWE‑77 (Command Injection), and its CVSS score of 9.4 reflects a high‑severity risk of remote code execution.

Affected Systems

RedPort:Optimizer wXa‑203, wXa‑213, and wXa‑223 versions up to 20260704 are impacted. The attack surfaces the /xgatev1/system/datetime.php file of the System Clock module, and the vendor has not yet provided a public fix.

Risk and Exploitability

The vulnerability can be triggered remotely, and although the EPSS score is not available, the high CVSS and public disclosure indicate that exploitation is plausible. It is not listed in the CISA KEV catalog, yet the potential to run arbitrary commands on the host constitutes a significant threat.

Generated by OpenCVE AI on September 1, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RedPort Optimizer to a version released after 20260704 that contains the patch for the datetime.php command injection.
  • Restrict or disable public access to the /xgatev1/system/datetime.php endpoint, ensuring only authenticated and authorized users can reach it.
  • If an upgrade is delayed, remove or comment out the exec call in /xgatev1/system/datetime.php, or replace it with a safe alternative that validates input arguments and prevents command injection.

Generated by OpenCVE AI on September 1, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title RedPort Optimizer wXa-223 System Clock datetime.php exec command injection
First Time appeared Redport
Redport optimizer Wxa-203
Redport optimizer Wxa-213
Redport optimizer Wxa-223
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:redport:optimizer_wxa-203:*:*:*:*:*:*:*:*
cpe:2.3:a:redport:optimizer_wxa-213:*:*:*:*:*:*:*:*
cpe:2.3:a:redport:optimizer_wxa-223:*:*:*:*:*:*:*:*
Vendors & Products Redport
Redport optimizer Wxa-203
Redport optimizer Wxa-213
Redport optimizer Wxa-223
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Redport Optimizer Wxa-203 Optimizer Wxa-213 Optimizer Wxa-223
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T22:45:37.776Z

Reserved: 2026-08-31T15:59:34.431Z

Link: CVE-2026-83524

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T23:16:35.650

Modified: 2026-08-31T23:16:35.650

Link: CVE-2026-83524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T00:30:05Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')