CVE-2026-20797

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
27/02/2026
Last modified:
27/02/2026

Description

A stack based buffer overflow exists in an API route of XWEB Pro version<br /> 1.12.1 and prior, enabling unauthenticated attackers to cause stack <br /> corruption and a termination of the program.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:copeland:xweb_300d_pro_firmware:*:*:*:*:*:*:*:* 1.12.1 (including)
cpe:2.3:h:copeland:xweb_300d_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:copeland:xweb_500d_pro_firmware:*:*:*:*:*:*:*:* 1.12.1 (including)
cpe:2.3:h:copeland:xweb_500d_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:copeland:xweb_500b_pro_firmware:*:*:*:*:*:*:*:* 1.12.1 (including)
cpe:2.3:h:copeland:xweb_500b_pro:-:*:*:*:*:*:*:*