CVE-2026-20797

MEDIUM

Copeland XWEB 300D PRO, 500D PRO, 500B PRO < 1.12.1 - Unauthenticated Stack-based Buffer Overflow

Title source: llm
STIX 2.1

Description

A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.

Scores

CVSS v3 4.3
EPSS 0.0078
EPSS Percentile 50.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-121 CWE-787
Status published
Products (6)
Copeland/Copeland XWEB 300D PRO < 1.12.1
Copeland/Copeland XWEB 500B PRO < 1.12.1
Copeland/Copeland XWEB 500D PRO < 1.12.1
copeland/xweb_300d_pro_firmware < 1.12.1
copeland/xweb_500b_pro_firmware < 1.12.1
copeland/xweb_500d_pro_firmware < 1.12.1
Published Feb 27, 2026
Tracked Since Feb 27, 2026