Executive brief
Copeland XWEB Pro is an industrial monitoring and control solution used to manage refrigeration and HVAC systems. A security flaw in the firmware update process allows an authorized user to run unauthorized commands on the device. This could lead to a complete takeover of the system, potentially disrupting critical cooling operations or allowing access to sensitive operational data.
Technical details
An OS command injection vulnerability (CWE-78) exists in the firmware update functionality of Copeland XWEB Pro. The flaw is located in the 'devices' field of the firmware update action, where malicious input is not properly neutralized before being executed by the underlying operating system. An authenticated attacker with network access can exploit this to achieve remote code execution (RCE) with the privileges of the application. While some assessments suggest a high complexity (AC:H), NVD's analysis indicates a lower complexity (AC:L) for authenticated users. Copeland has released patches and recommends updating to the latest version via their software update portal or the device's internal update menu.
Affected products
- Copeland XWEB 300D PRO <=1.12.1
- Copeland XWEB 500D PRO <=1.12.1
- Copeland XWEB 500B PRO <=1.12.1
Timeline
- 2026-02-26: advisory: CISA ICSA-26-057-10 published
- 2026-02-27: disclosed: NVD publication date
- 2026-06-04: other: CVE record modified by ICS-CERT