Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-83524: RedPort Optimizer wXa-223 enables remote command execution

CVE-2026-83524 · published 2 days ago
Summary

Versions wXa-203, wXa-213 and wXa-223 of RedPort Optimizer (up to the July 2026 release) contain a flaw in the system clock component that lets an attacker send specially‑crafted requests to the file datetime.php and cause the server to run any commands. This can be triggered from outside the network, giving a remote user control over the affected system. Apply any security update from the vendor immediately, or limit network access to the affected service and monitor for unusual activity.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
redport optimizer wxa-203 20260704
redport optimizer wxa-213 20260704
redport optimizer wxa-223 20260704
Original advisory text
RedPort Optimizer wXa-223 System Clock datetime.php exec command injection
A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-83524 · MITRE
Monitor software like this
Free during beta