Published:2026/09/04 Last Updated:2026/09/04
JVN#32505330
Multiple vulnerabilities in XING CPTrans-ME-X
Overview
XING CPTrans-ME-X contains multiple vulnerabilities.
Products Affected
- XING CPTrans-ME-X firmware versions prior to Ver 1.8.1.17
Description
CPTrans-ME-X provided by XING Inc. contains multiple vulnerabilities listed below.
- OS Command Injection (CWE-78)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
- CVE-2026-62928
- Improper processing of the input through the administrative port may lead to OS command injection.
- Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
- CVE-2026-66840
- Improper processing of the input through the administrative port may lead to the system information exposure.
- Use of Default Password (CWE-1393)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
- CVE-2026-69657
- The affected devices with the initial configuration have a default password for the Web UI.
- Use of Hard-coded Password (CWE-259)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
- CVE-2026-70403
- There is a password embedded in the firmware of the affected devices which allows unauthorized users to log in to the administrative port.
Impact
- Unauthenticated OS command injection (CVE-2026-62928)
- Sensitive system information exposure (CVE-2026-66840)
- Anyone with knowledge of the credentials may log in to the affected device (CVE-2026-69657, CVE-2026-70403)
Solution
Update the firmware
At the time of this JVN advisory publishing, the developer provides the firmware update to narrow the attack surface:
- the administrative port is disabled in the initial configuration
- the set of commands available when logged in is limited to only those necessary for maintenance purposes
Vendor Status
| Vendor | Link |
| Xing Inc. | CPTrans-ME-X (Text in Japanese) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Katsuhiko Sato(a.k.a. goroh_kun) of 00One, Inc. reported the issues to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-62928 |
|
CVE-2026-66840 |
|
|
CVE-2026-69657 |
|
|
CVE-2026-70403 |
|
| JVN iPedia |
JVNDB-2026-000128 |