CVE-2026-24452
An OS command injection
vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an
authenticated attacker to achieve remote code execution on the system by
supplying a crafted template file to the devices route.
vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an
authenticated attacker to achieve remote code execution on the system by
supplying a crafted template file to the devices route.
Vendor
Product
CWE
Yayın Tarihi
2026-02-27 02:16:18
Güncelleme
2026-02-27 23:08:17
Source Identifier
ics-cert@hq.dhs.gov
KEV Date Added
-