← Vulnerability feed

Vulnerability record · CVE-2026-20742 · published 27 February 2026

CVE-2026-20742: Copeland xweb 300d pro firmware os command injection vulnerability

Copeland · Xweb 300d Pro Firmware

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.

8.8 CVSS 3.1 High EPSS 1.5% · top 26.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20742 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-20797Copeland xweb 300d pro firmware out-of-bounds write vulnerabilityA stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corrupti…EPSS 0.82%9.8CVE-2026-25085Copeland xweb 500b pro firmware vulnerabilityA vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on…EPSS 0.50%9.8CVE-2026-21718Copeland xweb 300d pro firmware broken cryptographic algorithm vulnerabilityAn authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requ…EPSS 0.44%9.8CVE-2026-24663Copeland xweb 500b pro firmware os command injection vulnerabilityAn OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execut…EPSS 2.2%9.1CVE-2026-22877Copeland xweb 300d pro firmware path traversal vulnerabilityAn arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the s…EPSS 0.57%8.8CVE-2026-25196Copeland xweb 300d pro firmware os command injection vulnerabilityAn OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code executio…EPSS 1.9%8.8CVE-2026-25721Copeland xweb 300d pro firmware os command injection vulnerabilityAn OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code executio…EPSS 2.6%8.8CVE-2026-3037Copeland xweb 300d pro firmware os command injection vulnerabilityAn OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code executio…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2026-20742), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.