Executive brief
RedPort Optimizer is a performance management appliance used to optimize network and system operations. A command injection vulnerability in the System Clock component allows remote attackers to execute arbitrary system commands, potentially compromising the entire device and any networks it protects.
Technical details
A command injection vulnerability exists in the exec function of /xgatev1/system/datetime.php within the System Clock component of RedPort Optimizer. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary system commands through improper input validation. The attack is network-reachable and requires no prior authentication. Successful exploitation grants command execution with the privileges of the web service, potentially leading to complete system compromise. The vendor was contacted early but provided no response or patch.
Affected products
- RedPort Optimizer wXa-203 up to 20260704
- RedPort Optimizer wXa-213 up to 20260704
- RedPort Optimizer wXa-223 up to 20260704
Timeline
- 2026-08-31: disclosed: Publicly disclosed vulnerability