CVE-2026-25721 | Copeland XWEB 300D PRO/XWEB 500D PRO/XWEB 500B PRO up to 1.12.1 Restore Action API os command injection
A vulnerability was found in Copeland XWEB 300D PRO, XWEB 500D PRO and XWEB 500B PRO up to 1.12.1 and classified as critical. This affects an unknown part of the component Restore Action API. Such manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-25721. The attack can be executed remotely. There is not any exploit available.