CVE-2026-24689 | Copeland XWEB 300D PRO/XWEB 500D PRO/XWEB 500B PRO up to 1.12.1 Firmware Update Devices os command injection
A vulnerability classified as critical has been found in Copeland XWEB 300D PRO, XWEB 500D PRO and XWEB 500B PRO up to 1.12.1. Affected by this vulnerability is an unknown functionality of the component Firmware Update Handler. The manipulation of the argument Devices leads to os command injection.
This vulnerability is referenced as CVE-2026-24689. Remote exploitation of the attack is possible. No exploit is available.