CVE-2026-25085

EUVD-2026-8954
A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in
 which an unexpected return value from the authentication routine is 
later on processed as a legitimate value, resulting in an authentication
 bypass.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
copelandxweb_500b_pro_firmware
𝑥
≤ 1.12.1
copelandxweb_300d_pro_firmware
𝑥
≤ 1.12.1
copelandxweb_500d_pro_firmware
𝑥
≤ 1.12.1
𝑥
= Vulnerable software versions