CVE-2026-20797: Copeland Xweb 300d Pro Firmware
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.
Affected products
- Copeland Xweb 300d Pro Firmware: up to and including 1.12.1
- Copeland Xweb 500b Pro Firmware: up to and including 1.12.1
- Copeland Xweb 500d Pro Firmware: up to and including 1.12.1
Published 2026-02-27. Last modified 2026-06-17.