Critical Copeland XWEB Pro Flaw Lets Remote Attackers Take Control of Refrigeration Systems
Brief
A newly disclosed 23 vulnerabilities in Copeland XWEB Pro commercial refrigeration controllers, including an authentication bypass and predictable credential-generation flaws that can allow unauthenticated remote attackers to obtain root-level code execution.
The issues, disclosed by Claroty’s Team82 research unit, affect the Copeland XWEB Pro product family, including the XWEB300D PRO and XWEB500D PRO. Copeland has released firmware version 1. 13 to address the vulnerabilities.
XWEB Pro devices act as supervisory controllers in commercial refrigeration environments. They connect enterprise networks to distributed field controllers, allowing operators to remotely monitor alarms, review temperature records, and manage refrigeration equipment.
