PT-2026-84055 · Redports · Optimizer Wxa-223+2

·

CVE-2026-83524

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RedPort Optimizer wXa-203 versions prior to 20260704 RedPort Optimizer wXa-213 versions prior to 20260704 RedPort Optimizer wXa-223 versions prior to 20260704
Description A command injection issue exists in the System Clock component. A remote attacker can manipulate the exec() function within the /xgatev1/system/datetime.php file to execute arbitrary commands on the system.
Recommendations As a temporary workaround, restrict access to the /xgatev1/system/datetime.php file or disable the exec() function within that file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83524

Affected Products

Optimizer Wxa-203
Optimizer Wxa-213
Optimizer Wxa-223