VYPR

Xweb

by Xweb

CVEs (20)

  • CVE-2026-24663CriFeb 27, 2026
    risk 0.59cvss 9.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the…

  • CVE-2026-3037HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird SMS service URL and/or code via the utility route which is…

  • CVE-2026-25721HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server username and/or password fields of the restore action in the API…

  • CVE-2026-25196HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and/or password fields can lead to remote code execution when…

  • CVE-2026-25105HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the Modbus command tool in the debug route.

  • CVE-2026-25037HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which is later processed during system setup, enabling remote…

  • CVE-2026-24452HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

  • CVE-2026-23702HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in…

  • CVE-2026-25195HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

  • CVE-2026-25111HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.

  • CVE-2026-25109HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route.

  • CVE-2026-24695HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument fields within requests sent to the utility route,…

  • CVE-2026-24689HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update apply action.

  • CVE-2026-24517HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the firmware update route.

  • CVE-2026-21389HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.

  • CVE-2026-20910HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update action to achieve remote code…

  • CVE-2026-20742HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.

  • CVE-2026-20797MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.01

    A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.

  • CVE-2026-22877LowFeb 27, 2026
    risk 0.24cvss 3.7epss 0.01

    An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack.

  • CVE-2004-1838Mar 22, 2004
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.