Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-83524: RedPort Optimizer wXa-223 enables remote command execution
CVE-2026-83524 · published 2 days ago
Summary
Versions wXa-203, wXa-213 and wXa-223 of RedPort Optimizer (up to the July 2026 release) contain a flaw in the system clock component that lets an attacker send specially‑crafted requests to the file datetime.php and cause the server to run any commands. This can be triggered from outside the network, giving a remote user control over the affected system. Apply any security update from the vendor immediately, or limit network access to the affected service and monitor for unusual activity.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| redport | optimizer wxa-203 | 20260704 |
| redport | optimizer wxa-213 | 20260704 |
| redport | optimizer wxa-223 | 20260704 |
Original advisory text
RedPort Optimizer wXa-223 System Clock datetime.php exec command injection
A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
- https://vuldb.com/vuln/397374 vdb-entry technical-description
- https://vuldb.com/vuln/397374/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-83524 third-party-advisory
- https://vuldb.com/submit/880051 third-party-advisory
- https://uvxbywu62qm.feishu.cn/wiki/EA4TwFTx0ih9IhkJX5QcnCmlnSd?from=from_copylin... exploit
Severity
8.6
High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta