Skip to content
Threat Feed
critical advisory

Remote Command Injection in RedPort Optimizer wXa Series

RedPort Optimizer wXa-203, wXa-213, and wXa-223 devices running firmware up to 20260704 are vulnerable to unauthenticated remote code execution due to command injection in the System Clock component.

CVE search metadata

CVE search record: CVE-2026-83524. Severity: critical. CVSS: 9.9. KEV: no. Product: Optimizer wXa-203 (<= 20260704), Optimizer wXa-213 (<= 20260704), Optimizer wXa-223 (<= 20260704). Brief: Remote Command Injection in RedPort Optimizer wXa Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-redport-command-injection/

A critical vulnerability (CVE-2026-83524) exists in the RedPort Optimizer wXa series, specifically models wXa-203, wXa-213, and wXa-223 running firmware versions up to 20260704. The flaw resides within the System Clock component, specifically inside the 'exec' function located in '/xgatev1/system/datetime.php'. An unauthenticated remote attacker can supply malicious input to this endpoint to achieve command injection. Because the exploitation of this vulnerability has been disclosed publicly, the risk of exploitation by opportunistic threat actors is significantly elevated. Despite notification, the vendor has not provided a response or a patch to remediate this issue, leaving deployed devices exposed to remote exploitation. Defenders should monitor for unexpected HTTP POST or GET requests to the specified URI on these network-attached devices.

Impact

Successful exploitation of this vulnerability leads to unauthenticated remote code execution on the affected RedPort Optimizer network devices. This allows attackers to fully compromise the device, potentially facilitating lateral movement within the network, interception of satellite communication traffic routed through the Optimizer, or persistent access to the network edge. Given the nature of these devices as satellite gateways, a compromise could have severe operational consequences for maritime and remote-site connectivity.

Recommendation

  1. Restrict administrative access to the RedPort Optimizer management interface to trusted IP ranges only.
  2. Implement network egress filtering for these devices to prevent them from reaching unknown command-and-control infrastructure.
  3. Monitor web server logs for HTTP requests targeting '/xgatev1/system/datetime.php' containing suspicious parameters, such as shell metacharacters (e.g., ;, |, &, $, `).
  4. Segment these devices into an isolated VLAN to minimize the impact if they are compromised.

Immediate actions

Restrict network access to RedPort Optimizer management interface

IT Operations 24h

Threat Hunt

Search logs for requests to /xgatev1/system/datetime.php

T1203 high high confidence hunt now

Data: Web server logs

Mitigations

Network segmentation and access restriction

immediate IT Operations

CVE-2026-83524

Detection coverage 1

Detects CVE-2026-83524 Exploitation - Unauthenticated RCE via datetime.php

critical

Detects exploitation attempts against CVE-2026-83524 targeting the system clock component with shell metacharacters in the query string

sigma tactics: initial_access techniques: T1203 sources: webserver

Detection queries are available on the platform. Get full rules →