CVE-2026-25109 | Copeland XWEB 300D PRO/XWEB 500D PRO/XWEB 500B PRO up to 1.12.1 Devices os command injection
A vulnerability classified as critical was found in Copeland XWEB 300D PRO, XWEB 500D PRO and XWEB 500B PRO up to 1.12.1. Affected by this issue is some unknown functionality. The manipulation of the argument Devices results in os command injection.
This vulnerability is identified as CVE-2026-25109. The attack can be executed remotely. There is not any exploit available.