Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-09 and was added to the RWP archive on 2026-09-07.
Copeland XWEB Pro: 23 bugs, root RCE, and a PoC that lied about the temperature
Team82 at DEF CON 34 — unauthenticated path to root on XWEB Pro ≤1.12.1, Modbus control of field refrigeration, spoofed display while cooling is off. Copeland shipped 1.13.
Bottom line up front
CONFIRMED 9 August 2026 Team82 (DEF CON 34): 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers, 21 high. Unauthenticated attackers can chain to root RCE. Live lab: manipulate connected refrigeration over Modbus, set displayed temperature independently of the probe, disable cooling/fans/compressor while the display still looks healthy — silent spoilage path. Firmware 1.13. Example CVE-2026-24695: authenticated OS command injection via OpenSSL argument fields (CVSS 8.0) on XWEB 300D/500D/500B PRO ≤1.12.1; sibling unauth injection on libraries-install (CVE-2026-24663 in Team82's own CVE blurb). Industrial Cyber matches the 23/21 counts and the spoof-display PoC. In-the-wild: UNKNOWN. Process impact in lab: CONFIRMED by researchers; production victims: UNKNOWN.
Historical backfill of 9 August 2026 reporting; added 7 September 2026.
What happened
A supervisory controller that talks Modbus to XR60CX-class field units became a lie factory: the HMI shows -18°C while the fans are off.
Why it mattered
Cold chain is food, pharma, and blood. Integrity of the display is a safety control. Patching 1.13 without checking whether the box was WAN-exposed is incomplete.
Who / what was affected
XWEB Pro 1.12.1 and prior, named SKUs in the CVE record.
Technical context
Unauth command injection + auth bypass + predictable password generation (Industrial Cyber). Take XWEB off internet; patch 1.13; verify Modbus peers.
Exploitation / threat status at the time
CONFIRMED research + vendor patch.
UNKNOWN exploitation.
What defenders should have done
- 1.13 immediately.
- Independent temperature probes that are not the XWEB display.
- Alert on cooling-off vs setpoint mismatch.
RWP assessment
Confidence: High on the lab physics. This is OT with a grocery-store outcome.
Defensive actions
- Firmware + no WAN.
- Secondary sensors.
- Incident trigger: unexplained spoilage, not just a SIEM alert.
Sources
- Claroty Team82 — Chilling discoveries: Copeland XWEB Pro
- Industrial Cyber — Team82 exposes Copeland XWEB Pro vulnerabilities
- Claroty — CVE-2026-24695 disclosure