CVE-2026-83524
nicheAuthenticated Command Injection in RedPort Optimizer wXa Satellite Appliances
CVE-2026-83524 is a command injection flaw (CWE-74/CWE-77) in the exec function of /xgatev1/system/datetime.php, part of the System Clock component, in RedPort Optimizer wXa-203, wXa-213 and wXa-223 firmware up to and including build 20260704. A remote attacker with low-privileged (authenticated) access to the device's web interface can manipulate input passed to this handler to inject and run operating-system commands. Successful exploitation yields command execution on the appliance with high impact on confidentiality, integrity and availability, reflected in the CVSS 4.0 score of 8.6 (high). Affected users are operators of these RedPort satellite-communication Optimizer appliances, which are typically deployed on vessels and at remote sites; all units running firmware up to 20260704 are vulnerable. The exploit has been publicly disclosed and may be used, the vendor was contacted early but did not respond, no fix is announced, and the flaw is not yet in CISA KEV with an EPSS 30-day exploitation probability of about 1.7%.
What to do: Because the vendor did not respond and no fixed firmware is announced, treat every build up to and including 20260704 as vulnerable and reduce exposure: restrict access to the device's web/admin interface (including the /xgatev1/ endpoints) to trusted networks or VPN and avoid exposing it directly to the internet. Monitor HTTP and device logs for unusual requests to /xgatev1/system/datetime.php, and watch for an updated firmware release from RedPort.
| RedPort Optimizer wXa-203 | up to and including firmware build 20260704 |
| RedPort Optimizer wXa-213 | up to and including firmware build 20260704 |
| RedPort Optimizer wXa-223 | up to and including firmware build 20260704 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.