Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Copeland XWEB 300D PRO — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Copeland XWEB 300D PRO, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities associated with the Copeland XWEB 300D PRO industrial controller, categorized by Common Weakness Enumeration (CWE) classifications and relevant security tags. It aggregates historical and current security issues affecting this specific piece of HVAC control hardware, covering data from the initial release through recent updates. By compiling reports from various sources, the page provides a centralized view of flaws ranging from privilege escalation and buffer overflows to insecure default configurations and input validation errors. Users can utilize this resource to track vendor advisories as they are published, helping administrators stay informed about patches and mitigations for the Copeland XWEB 300D PRO. Furthermore, the aggregated data allows security analysts to understand the broader context of specific weakness classes within this product family, revealing trends in code quality or design flaws. The history of vulnerabilities enables teams to assess the long-term security posture of the device and prioritize remediation efforts based on severity and exploitability. This collection serves as a practical reference for system integrators, maintenance technicians, and security engineers who need to evaluate risks before deploying or upgrading the equipment. The information presented here is strictly technical, aimed at supporting informed decision-making and enhancing the operational security of environments relying on Copeland control systems.

Vendor: Copeland

CVE IDTitleCVSSSeverityPublished
CVE-2026-3037 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-20797 Copeland XWEB and XWEB Pro Stack-based Buffer Overflow 4.3 Medium2026-02-27
CVE-2026-22877 Copeland XWEB and XWEB Pro Path Traversal CWE-22 3.7 Low2026-02-27
CVE-2026-25037 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-25196 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-20764 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-25721 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-23702 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-24452 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-25105 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-24695 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-20902 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-25109 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-24689 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-20910 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-25195 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-24517 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-20742 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-25111 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-21389 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 8.0 High2026-02-27
CVE-2026-24663 Copeland XWEB and XWEB Pro OS Command Injection CWE-78 9.0 Critical2026-02-27
CVE-2026-21718 Copeland XWEB and XWEB Pro Use of a Broken or Risky Cryptographic Algorithm CWE-327 10.0 Critical2026-02-27
CVE-2026-25085 Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value CWE-394 8.6 High2026-02-27

All 23 known CVE vulnerabilities affecting Copeland XWEB 300D PRO with full Chinese analysis, references, and POCs where available.