Junglewise Threat Intelligence

CVE-2026-25109: Copeland XWEB Pro OS command injection in get setup route

CVE-2026-25109 · Severity: high · CVSS 8 · Published 2026-02-27

Technologies: Copeland Xweb 500b Pro Firmware, Copeland Xweb 500d Pro Firmware, Copeland Xweb 500b Pro, Copeland Xweb 300d Pro Firmware, Copeland Xweb 300d Pro, Copeland Xweb 500d Pro. Vendors: Copeland.

Executive brief

Copeland XWEB Pro is a monitoring and control system used in commercial facilities to manage refrigeration and HVAC systems. A security vulnerability allows an authorized user to run unauthorized commands on the device's operating system. This could lead to a complete takeover of the system, potentially disrupting critical cooling operations or exposing sensitive environmental data.

Technical details

An OS command injection vulnerability (CWE-78) exists in the web interface of Copeland XWEB Pro. The flaw is located within the 'get setup' route, where the application fails to properly neutralize malicious input provided in the 'devices' field. An authenticated attacker with network access can exploit this by sending a crafted request to execute arbitrary commands with the privileges of the web server. This can lead to full system compromise. The vulnerability affects versions 1.12.1 and prior; users are advised to update to the latest firmware version via the Copeland software update page or the device's internal update menu.

Affected products

  • Copeland XWEB 300D PRO <=1.12.1
  • Copeland XWEB 500D PRO <=1.12.1
  • Copeland XWEB 500B PRO <=1.12.1

Timeline

  • 2026-02-26: advisory: CISA ICSA-26-057-10 published
  • 2026-02-27: disclosed: NVD publication date
  • 2026-06-04: other: CVE record modified by ICS-CERT

References

Related threats