CVE-2026-25085
Received
Received - Intake
Authentication Bypass in Copeland XWEB Pro
Publication date: 2026-02-27
Last updated on: 2026-03-09
Assigner: ICS-CERT
Description
Description
A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in
which an unexpected return value from the authentication routine is
later on processed as a legitimate value, resulting in an authentication
bypass.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| copeland | xweb_500b_pro_firmware | to 1.12.1 (inc) |
| copeland | xweb_300d_pro_firmware | to 1.12.1 (inc) |
| copeland | xweb_500d_pro_firmware | to 1.12.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-394 | The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product. |