CVE-2026-62928
—Unauthenticated OS Command Injection in XING CPTrans-ME-X
XING CPTrans-ME-X contains an OS command injection flaw (CWE-78) that allows an unauthenticated remote attacker to inject and execute arbitrary operating-system commands. Because the CVSS 4.0 vector shows network attack vector, low attack complexity, and no privileges or user interaction required (AV:N/PR:N/UI:N), a crafted request sent over the network to the affected product is sufficient to trigger the flaw. Successful exploitation yields high impact to the confidentiality, integrity, and availability of the compromised system, which is consistent with full command execution under the privileges of the affected service. Any organization running XING CPTrans-ME-X, particularly where the device or application is reachable from untrusted networks, is exposed. There is currently no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating a 1.2% probability of exploitation within 30 days.
What to do: Inventory your environment for CPTrans-ME-X deployments and check whether the product is exposed to untrusted networks or the internet, restricting access with firewall or ACL rules in the meantime. Watch the JPCERT/JVN advisory (the CNA is [email protected]) and the vendor's site for patched release details, and apply the fix as soon as fixed versions are published. Until patched, limit network reachability of the product to trusted management networks only.
| XING CPTrans-ME-X | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.