Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-09 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Copeland XWEB Pro: 23 bugs, root RCE, and a PoC that lied about the temperature

Team82 at DEF CON 34 — unauthenticated path to root on XWEB Pro ≤1.12.1, Modbus control of field refrigeration, spoofed display while cooling is off. Copeland shipped 1.13.

RWP Ventures · 2026-09-07 · event 2026-08-09 · 1 min read · priority 8.4

Bottom line up front

CONFIRMED 9 August 2026 Team82 (DEF CON 34): 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers, 21 high. Unauthenticated attackers can chain to root RCE. Live lab: manipulate connected refrigeration over Modbus, set displayed temperature independently of the probe, disable cooling/fans/compressor while the display still looks healthy — silent spoilage path. Firmware 1.13. Example CVE-2026-24695: authenticated OS command injection via OpenSSL argument fields (CVSS 8.0) on XWEB 300D/500D/500B PRO ≤1.12.1; sibling unauth injection on libraries-install (CVE-2026-24663 in Team82's own CVE blurb). Industrial Cyber matches the 23/21 counts and the spoof-display PoC. In-the-wild: UNKNOWN. Process impact in lab: CONFIRMED by researchers; production victims: UNKNOWN.

Historical backfill of 9 August 2026 reporting; added 7 September 2026.

What happened

A supervisory controller that talks Modbus to XR60CX-class field units became a lie factory: the HMI shows -18°C while the fans are off.

Why it mattered

Cold chain is food, pharma, and blood. Integrity of the display is a safety control. Patching 1.13 without checking whether the box was WAN-exposed is incomplete.

Who / what was affected

XWEB Pro 1.12.1 and prior, named SKUs in the CVE record.

Technical context

Unauth command injection + auth bypass + predictable password generation (Industrial Cyber). Take XWEB off internet; patch 1.13; verify Modbus peers.

Exploitation / threat status at the time

CONFIRMED research + vendor patch.

UNKNOWN exploitation.

What defenders should have done

  1. 1.13 immediately.
  2. Independent temperature probes that are not the XWEB display.
  3. Alert on cooling-off vs setpoint mismatch.

RWP assessment

Confidence: High on the lab physics. This is OT with a grocery-store outcome.

Defensive actions

  1. Firmware + no WAN.
  2. Secondary sensors.
  3. Incident trigger: unexplained spoilage, not just a SIEM alert.

Sources

  1. Claroty Team82 — Chilling discoveries: Copeland XWEB Pro
  2. Industrial Cyber — Team82 exposes Copeland XWEB Pro vulnerabilities
  3. Claroty — CVE-2026-24695 disclosure