CVE-2025-13826

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
21/04/2026
Last modified:
21/04/2026

Description

Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vulnerability is caused by inadequate validation of user-supplied input. An attacker can exploit this vulnerability by sending malicious requests. If the vulnerability is successfully exploited, the application can be made to stop responding, resulting in a DoS condition. It is possible to manually restart the application.