Impact
The vulnerable System Clock component of RedPort Optimizer allows an attacker to inject arbitrary operating‑system commands through the exec function in datetime.php. The flaw is classified as CWE‑74 and CWE‑77, and its CVSS score of 9.4 reflects a high‑severity risk of remote code execution.
Affected Systems
RedPort:Optimizer wXa‑203, wXa‑213, and wXa‑223 versions up to 20260704 are impacted. The attack surfaces the /xgatev1/system/datetime.php file of the System Clock module, and the vendor has not yet provided a public fix.
Risk and Exploitability
The vulnerability can be triggered remotely, and with an EPSS score of 2%, the likelihood of exploitation is low but non‑zero. However, the high CVSS and public disclosure indicate that exploitation is still plausible. It is not listed in the CISA KEV catalog, yet the potential to run arbitrary commands on the host constitutes a significant threat.
OpenCVE Enrichment