CVE-2026-20902 | Copeland XWEB 300D PRO/XWEB 500D PRO/XWEB 500B PRO up to 1.12.1 os command injection
A vulnerability categorized as critical has been discovered in Copeland XWEB 300D PRO, XWEB 500D PRO and XWEB 500B PRO up to 1.12.1. The affected element is an unknown function. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-20902. It is possible to launch the attack remotely. No exploit is available.