PT-2026-84055 · Redports · Optimizer Wxa-223+2
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RedPort Optimizer wXa-203 versions prior to 20260704
RedPort Optimizer wXa-213 versions prior to 20260704
RedPort Optimizer wXa-223 versions prior to 20260704
Description
A command injection issue exists in the System Clock component. A remote attacker can manipulate the
exec() function within the /xgatev1/system/datetime.php file to execute arbitrary commands on the system.Recommendations
As a temporary workaround, restrict access to the
/xgatev1/system/datetime.php file or disable the exec() function within that file to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Optimizer Wxa-203
Optimizer Wxa-213
Optimizer Wxa-223