CVE-2026-62928: Command Injection
Published Sep 4, 2026
·Updated
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
Affected Software
1 affected component
XING CPTrans-ME-X
Event History
Sep 4, 2026
CVE Published
via MITRE·06:31 AM
Data Sourced
via MITRE·06:31 AM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No. The vulnerability is described as allowing unauthenticated OS command injection, and the supplied vector indicates no privileges or user interaction are required.
2
What is the potential impact of successful exploitation?
The supplied severity vector rates confidentiality, integrity, and availability impact as high. An attacker able to exploit the issue could therefore potentially compromise data confidentiality, alter data or system behavior, and disrupt availability.