A newly reported set of 23 vulnerabilities has been identified in Copeland’s XWEB Pro commercial refrigeration controller lineup, including an authentication bypass vulnerability that allows unauthenticated remote attackers to gain root-level code execution. The flaws were discovered by Claroty's Team82 research team and affect the XWEB300D PRO and XWEB500D PRO models within the Copeland XWEB Pro product line. These devices function as supervisory controllers in commercial refrigeration environments, connecting enterprise networks with field-level controllers, enabling operators to monitor alarms, review temperature records, and manage refrigeration equipment remotely.

Since Lua considers tables truthy values, the router accepted the malformed authentication object and granted access to restricted administrative API routes.

According to Team82, multiple functions that handle tasks such as network configuration, contact list imports, and firmware updates concatenate user-controlled input into operating system commands. The proof of concept kept the temperature display synchronized with the legitimate probe reading while disabling cooling fans, causing the refrigerator to warm up without alerting an operator. Affected XWEB Pro systems should immediately deploy firmware 1.13, remove management interfaces from direct Internet exposure, segment operational networks, restrict administrative access, and monitor for unusual SSH, web, Modbus, and controller-configuration activity.

Utilize in-browser data inspection from ANY.RUN to detect, investigate, and respond swiftly, enhancing your SOC's effectiveness while reducing Mean Time To Repair (MTTR).