Remote Command Injection in RedPort Optimizer wXa Series
RedPort Optimizer wXa-203, wXa-213, and wXa-223 devices running firmware up to 20260704 are vulnerable to unauthenticated remote code execution due to command injection in the System Clock component.
CVE search metadata
CVE search record: CVE-2026-83524. Severity: critical. CVSS: 9.9. KEV: no. Product: Optimizer wXa-203 (<= 20260704), Optimizer wXa-213 (<= 20260704), Optimizer wXa-223 (<= 20260704). Brief: Remote Command Injection in RedPort Optimizer wXa Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-redport-command-injection/
A critical vulnerability (CVE-2026-83524) exists in the RedPort Optimizer wXa series, specifically models wXa-203, wXa-213, and wXa-223 running firmware versions up to 20260704. The flaw resides within the System Clock component, specifically inside the 'exec' function located in '/xgatev1/system/datetime.php'. An unauthenticated remote attacker can supply malicious input to this endpoint to achieve command injection. Because the exploitation of this vulnerability has been disclosed publicly, the risk of exploitation by opportunistic threat actors is significantly elevated. Despite notification, the vendor has not provided a response or a patch to remediate this issue, leaving deployed devices exposed to remote exploitation. Defenders should monitor for unexpected HTTP POST or GET requests to the specified URI on these network-attached devices.
Impact
Successful exploitation of this vulnerability leads to unauthenticated remote code execution on the affected RedPort Optimizer network devices. This allows attackers to fully compromise the device, potentially facilitating lateral movement within the network, interception of satellite communication traffic routed through the Optimizer, or persistent access to the network edge. Given the nature of these devices as satellite gateways, a compromise could have severe operational consequences for maritime and remote-site connectivity.
Recommendation
- Restrict administrative access to the RedPort Optimizer management interface to trusted IP ranges only.
- Implement network egress filtering for these devices to prevent them from reaching unknown command-and-control infrastructure.
- Monitor web server logs for HTTP requests targeting '/xgatev1/system/datetime.php' containing suspicious parameters, such as shell metacharacters (e.g., ;, |, &, $, `).
- Segment these devices into an isolated VLAN to minimize the impact if they are compromised.
Immediate actions
Restrict network access to RedPort Optimizer management interface
Threat Hunt
Search logs for requests to /xgatev1/system/datetime.php
Data: Web server logs
Mitigations
Network segmentation and access restriction
CVE-2026-83524
Detection coverage 1
Detects CVE-2026-83524 Exploitation - Unauthenticated RCE via datetime.php
criticalDetects exploitation attempts against CVE-2026-83524 targeting the system clock component with shell metacharacters in the query string
Detection queries are available on the platform. Get full rules →