{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/redport/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redport:optimizer_wxa-203:*:*:*:*:*:*:*:*","cpe:2.3:a:redport:optimizer_wxa-213:*:*:*:*:*:*:*:*","cpe:2.3:a:redport:optimizer_wxa-223:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-83524"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Optimizer wXa-203 (\u003c= 20260704)","Optimizer wXa-213 (\u003c= 20260704)","Optimizer wXa-223 (\u003c= 20260704)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["RedPort"],"content_html":"\u003cp\u003eA critical vulnerability (CVE-2026-83524) exists in the RedPort Optimizer wXa series, specifically models wXa-203, wXa-213, and wXa-223 running firmware versions up to 20260704. The flaw resides within the System Clock component, specifically inside the 'exec' function located in '/xgatev1/system/datetime.php'. An unauthenticated remote attacker can supply malicious input to this endpoint to achieve command injection. Because the exploitation of this vulnerability has been disclosed publicly, the risk of exploitation by opportunistic threat actors is significantly elevated. Despite notification, the vendor has not provided a response or a patch to remediate this issue, leaving deployed devices exposed to remote exploitation. Defenders should monitor for unexpected HTTP POST or GET requests to the specified URI on these network-attached devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to unauthenticated remote code execution on the affected RedPort Optimizer network devices. This allows attackers to fully compromise the device, potentially facilitating lateral movement within the network, interception of satellite communication traffic routed through the Optimizer, or persistent access to the network edge. Given the nature of these devices as satellite gateways, a compromise could have severe operational consequences for maritime and remote-site connectivity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict administrative access to the RedPort Optimizer management interface to trusted IP ranges only.\u003c/li\u003e\n\u003cli\u003eImplement network egress filtering for these devices to prevent them from reaching unknown command-and-control infrastructure.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests targeting '/xgatev1/system/datetime.php' containing suspicious parameters, such as shell metacharacters (e.g., ;, |, \u0026amp;, $, `).\u003c/li\u003e\n\u003cli\u003eSegment these devices into an isolated VLAN to minimize the impact if they are compromised.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T01:01:23Z","date_published":"2026-09-01T01:01:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-redport-command-injection/","summary":"RedPort Optimizer wXa-203, wXa-213, and wXa-223 devices running firmware up to 20260704 are vulnerable to unauthenticated remote code execution due to command injection in the System Clock component.","title":"Remote Command Injection in RedPort Optimizer wXa Series","url":"https://feed.craftedsignal.io/briefs/2026-09-redport-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - RedPort","version":"https://jsonfeed.org/version/1.1"}