Published:2026/09/04  Last Updated:2026/09/04

JVN#32505330
Multiple vulnerabilities in XING CPTrans-ME-X

Overview

XING CPTrans-ME-X contains multiple vulnerabilities.

Products Affected

  • XING CPTrans-ME-X firmware versions prior to Ver 1.8.1.17

Description

CPTrans-ME-X provided by XING Inc. contains multiple vulnerabilities listed below.

  • OS Command Injection (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
    • CVE-2026-62928
    • Improper processing of the input through the administrative port may lead to OS command injection.
  • Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
    • CVE-2026-66840
    • Improper processing of the input through the administrative port may lead to the system information exposure.
  • Use of Default Password (CWE-1393)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
    • CVE-2026-69657
    • The affected devices with the initial configuration have a default password for the Web UI.
  • Use of Hard-coded Password (CWE-259)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
    • CVE-2026-70403
    • There is a password embedded in the firmware of the affected devices which allows unauthorized users to log in to the administrative port.

Impact

  • Unauthenticated OS command injection (CVE-2026-62928)
  • Sensitive system information exposure (CVE-2026-66840)
  • Anyone with knowledge of the credentials may log in to the affected device (CVE-2026-69657, CVE-2026-70403)

Solution

Update the firmware
At the time of this JVN advisory publishing, the developer provides the firmware update to narrow the attack surface:

  • the administrative port is disabled in the initial configuration
  • the set of commands available when logged in is limited to only those necessary for maintenance purposes
According to the developer, an update via FOTA (Firmware Over-The-Air) was implemented for the affected products in April 2026.

Vendor Status

Vendor Link
Xing Inc. CPTrans-ME-X (Text in Japanese)

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Katsuhiko Sato(a.k.a. goroh_kun) of 00One, Inc. reported the issues to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-62928
CVE-2026-66840
CVE-2026-69657
CVE-2026-70403
JVN iPedia JVNDB-2026-000128