ZeroHour

CVE-2026-62928

Unauthenticated OS Command Injection in XING CPTrans-ME-X

CVSS 4.0
9.3 critical
EPSS
1%p67
Published
()
Modified
AI analysis

XING CPTrans-ME-X contains an OS command injection flaw (CWE-78) that allows an unauthenticated remote attacker to inject and execute arbitrary operating-system commands. Because the CVSS 4.0 vector shows network attack vector, low attack complexity, and no privileges or user interaction required (AV:N/PR:N/UI:N), a crafted request sent over the network to the affected product is sufficient to trigger the flaw. Successful exploitation yields high impact to the confidentiality, integrity, and availability of the compromised system, which is consistent with full command execution under the privileges of the affected service. Any organization running XING CPTrans-ME-X, particularly where the device or application is reachable from untrusted networks, is exposed. There is currently no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating a 1.2% probability of exploitation within 30 days.

What to do: Inventory your environment for CPTrans-ME-X deployments and check whether the product is exposed to untrusted networks or the internet, restricting access with firewall or ACL rules in the meantime. Watch the JPCERT/JVN advisory (the CNA is [email protected]) and the vendor's site for patched release details, and apply the fix as soon as fixed versions are published. Until patched, limit network reachability of the product to trusted management networks only.

Affected
XING CPTrans-ME-X
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.