<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Optimizer WXa-213 (&lt;= 20260704) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/optimizer-wxa-213--20260704/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 01:01:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/optimizer-wxa-213--20260704/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in RedPort Optimizer wXa Series</title><link>https://feed.craftedsignal.io/briefs/2026-09-redport-command-injection/</link><pubDate>Tue, 01 Sep 2026 01:01:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-redport-command-injection/</guid><description>RedPort Optimizer wXa-203, wXa-213, and wXa-223 devices running firmware up to 20260704 are vulnerable to unauthenticated remote code execution due to command injection in the System Clock component.</description><content:encoded><![CDATA[<p>A critical vulnerability (CVE-2026-83524) exists in the RedPort Optimizer wXa series, specifically models wXa-203, wXa-213, and wXa-223 running firmware versions up to 20260704. The flaw resides within the System Clock component, specifically inside the 'exec' function located in '/xgatev1/system/datetime.php'. An unauthenticated remote attacker can supply malicious input to this endpoint to achieve command injection. Because the exploitation of this vulnerability has been disclosed publicly, the risk of exploitation by opportunistic threat actors is significantly elevated. Despite notification, the vendor has not provided a response or a patch to remediate this issue, leaving deployed devices exposed to remote exploitation. Defenders should monitor for unexpected HTTP POST or GET requests to the specified URI on these network-attached devices.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to unauthenticated remote code execution on the affected RedPort Optimizer network devices. This allows attackers to fully compromise the device, potentially facilitating lateral movement within the network, interception of satellite communication traffic routed through the Optimizer, or persistent access to the network edge. Given the nature of these devices as satellite gateways, a compromise could have severe operational consequences for maritime and remote-site connectivity.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict administrative access to the RedPort Optimizer management interface to trusted IP ranges only.</li>
<li>Implement network egress filtering for these devices to prevent them from reaching unknown command-and-control infrastructure.</li>
<li>Monitor web server logs for HTTP requests targeting '/xgatev1/system/datetime.php' containing suspicious parameters, such as shell metacharacters (e.g., ;, |, &amp;, $, `).</li>
<li>Segment these devices into an isolated VLAN to minimize the impact if they are compromised.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>