Junglewise Threat Intelligence

CVE-2026-62928: XING CPTrans-ME-X OS command injection in administrative port

CVE-2026-62928 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Technologies: XING CPTrans-ME-X. Vendors: XING.

Executive brief

The XING CPTrans-ME-X is a communications adapter used in karaoke systems to manage network connectivity. An unauthenticated attacker can inject arbitrary OS commands through the administrative port, potentially allowing complete system compromise, data theft, or service disruption. The vulnerability requires no authentication and can be exploited remotely with minimal complexity.

Technical details

The vulnerability is an OS Command Injection (CWE-78) in the administrative port of CPTrans-ME-X firmware versions prior to 1.8.1.17. Improper input processing on the administrative interface allows an unauthenticated attacker to inject arbitrary commands via network access. An attacker can achieve remote code execution with full system privileges, leading to complete device compromise. Vendor has released a firmware update disabling the administrative port in initial configuration and restricting available commands; FOTA (Firmware Over-The-Air) updates were made available from April 2026.

Affected products

  • XING CPTrans-ME-X prior to 1.8.1.17

Timeline

  • 2026-09-04: disclosed
  • 2026-04: patched: FOTA firmware update available; administrative port disabled by default in patched version

References

Related threats